You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please help me reproduce this or any other conda dependency vulnerabilities.
To Reproduce
Steps to reproduce the behavior:
Convert this environment.yml file-code to conda list explicit:
name: jake-test
channels:
conda-force
defaults
dependencies:
openssl=1.1.1d
Once the conda explicit list is available (env.txt), run the Jake conda scanner against it using the following command:
'jake -w ddt -t CONDA -f "env.txt"'
The Jake-conda scanner results will show 6 Audited Vulnerabilities and 0 Vulnerabilities Found.
Expected behavior
Based on the Sonatype documentation in the shared link, above, I expect the Jake-conda scanner to return at least 1 Vulnerability Found in the scan results.
Screenshots
Screenshot from Sonatype link, showing known vulnerability:
Here are my actual results showing no vulnerabilities. The results are from an Azure DevOps pipeline:
Here is what the env.txt file looks like:
Desktop (please complete the following information):
-conda version 23.11.0
-running code in Azure DevOps
Additional context
My goal is to reproduce any vulnerabilities using Jake's Conda scanner.
The text was updated successfully, but these errors were encountered:
Describe the bug
I can't get Jake-conda scanner to recognize known vulnerabilities. Based on a screenshot from this Jake-Sonatype documentation (https://blog.sonatype.com/how-to-easily-identify-conda-vulnerabilities-using-sonatype-jake), I should get a vulnerability when I scan for this Conda dependency: [email protected]. However, when I run the scanner, there are zero vulnerabilities found.
Please help me reproduce this or any other conda dependency vulnerabilities.
To Reproduce
Steps to reproduce the behavior:
name: jake-test
channels:
dependencies:
Once the conda explicit list is available (env.txt), run the Jake conda scanner against it using the following command:
'jake -w ddt -t CONDA -f "env.txt"'
The Jake-conda scanner results will show 6 Audited Vulnerabilities and 0 Vulnerabilities Found.
Expected behavior
Based on the Sonatype documentation in the shared link, above, I expect the Jake-conda scanner to return at least 1 Vulnerability Found in the scan results.
Screenshots
![MicrosoftTeams-image (14)](https://private-user-images.githubusercontent.com/80787613/304254091-ce307388-2669-4a71-a1d1-166f82f391a9.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk1NTg5MzQsIm5iZiI6MTczOTU1ODYzNCwicGF0aCI6Ii84MDc4NzYxMy8zMDQyNTQwOTEtY2UzMDczODgtMjY2OS00YTcxLWExZDEtMTY2ZjgyZjM5MWE5LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTQlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE0VDE4NDM1NFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWVmYzczMTkxOWFmZjI0ZWQ5YzQ4ODlkZDc4NGRiYjA4NWMxYTYyMzA1YzdlYTdmNjBmNzE5OWQxNzI5ZWYxMTgmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.LQ84qAwRNjtMjl5nydCL-tTzixpZse-3KGek3VElRhE)
Screenshot from Sonatype link, showing known vulnerability:
Here are my actual results showing no vulnerabilities. The results are from an Azure DevOps pipeline:
![actual scan results](https://private-user-images.githubusercontent.com/80787613/304251103-b035f6c3-d9aa-4cbf-86c1-3491ffcce7de.jpg?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk1NTg5MzQsIm5iZiI6MTczOTU1ODYzNCwicGF0aCI6Ii84MDc4NzYxMy8zMDQyNTExMDMtYjAzNWY2YzMtZDlhYS00Y2JmLTg2YzEtMzQ5MWZmY2NlN2RlLmpwZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTQlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE0VDE4NDM1NFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWY3YjlhN2MzZmU2MWVjNmViNzI4MjRlMDljMzg3MmFlMTNlODAzZGY0MjBmMTc4ZTBmMTE0YTEyZTQ2OGViMWMmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.Tt2ABMAghaPlREGV_tov6ighM4tJppkGZ9P76JnDh68)
Here is what the env.txt file looks like:
![env txt contents](https://private-user-images.githubusercontent.com/80787613/304253747-4e8b0515-852d-4cbd-b3d0-9b0ee6f5cdd4.jpg?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk1NTg5MzQsIm5iZiI6MTczOTU1ODYzNCwicGF0aCI6Ii84MDc4NzYxMy8zMDQyNTM3NDctNGU4YjA1MTUtODUyZC00Y2JkLWIzZDAtOWIwZWU2ZjVjZGQ0LmpwZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTQlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE0VDE4NDM1NFomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTk3YjZhODJkN2Q5ZGFiNTAyNTE5ZjNmNTA2ZTk0YTY4OWY5MGQ4MmM1MmVjZjE1MTkzNzAwMmI4NDQwYmQ1NjkmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.fjVp8JnwDOAxXngoTG3VIV15r4DPA_-dC_Ar-eVC2C4)
Desktop (please complete the following information):
-conda version 23.11.0
-running code in Azure DevOps
Additional context
My goal is to reproduce any vulnerabilities using Jake's Conda scanner.
The text was updated successfully, but these errors were encountered: