Skip to content
This repository has been archived by the owner on Oct 2, 2024. It is now read-only.

Static Code Analysis - volur-v1-backend #31

Static Code Analysis - volur-v1-backend

Static Code Analysis - volur-v1-backend #31

Triggered via repository dispatch March 5, 2024 11:51
@veracode-workflow-appveracode-workflow-app[bot]
source-code-pipeline-scan 11e101e
Status Failure
Total duration 1m 33s
Artifacts 3

veracode-code-analysis.yml

on: repository_dispatch
register  /  create_check_run
3s
register / create_check_run
build  /  ...  /  build
5s
build / build-source-code-scan / build
build  /  ...  /  build
build / build-dot-net-package / build
build  /  ...  /  build
build / build-go-package / build
build  /  ...  /  build
build / build-java-gradle / build
build  /  ...  /  build
build / build-java-maven / build
pipeline_scan  /  pipeline scan
1m 3s
pipeline_scan / pipeline scan
policy_scan  /  policy scan
policy_scan / policy scan
Fit to window
Zoom out
Zoom in

Annotations

1 error and 3 warnings
pipeline_scan / pipeline scan
[05 Mar 2024 11:51:54,0865] PIPELINE-SCAN INFO: Pipeline Scan Tool Version 23.11.0-0. [05 Mar 2024 11:51:54,0874] PIPELINE-SCAN INFO: Getting resource policy Veracode Recommended Medium + SCA [05 Mar 2024 11:51:54,0905] PIPELINE-SCAN INFO: Successfully retrieved the policy [05 Mar 2024 11:51:54,0905] PIPELINE-SCAN INFO: Policy name: Veracode Recommended Medium + SCA [05 Mar 2024 11:51:54,0906] PIPELINE-SCAN INFO: CWE filter: [05 Mar 2024 11:51:54,0906] PIPELINE-SCAN INFO: Severity filter: 4, 5, [05 Mar 2024 11:51:54,0907] PIPELINE-SCAN INFO: Beginning scanning of './veracode_artifact_directory/veracode.zip'. [05 Mar 2024 11:51:54,0908] PIPELINE-SCAN INFO: Sending 4273391 bytes to the server for analysis. [05 Mar 2024 11:52:01,0454] PIPELINE-SCAN INFO: Upload complete. [05 Mar 2024 11:52:01,0454] PIPELINE-SCAN INFO: Scan ID: 0f88d97d-32ab-411f-aaa9-fd8add7a38a8 [05 Mar 2024 11:52:02,0197] PIPELINE-SCAN INFO: Analysis Started. =========================== Found 1 Scannable modules. =========================== JS files within veracode.zip [05 Mar 2024 11:52:43,0616] PIPELINE-SCAN INFO: Analysis Complete. [05 Mar 2024 11:52:43,0627] PIPELINE-SCAN INFO: Analysis Results: Received 13425 bytes in 48720ms. [05 Mar 2024 11:52:43,0632] PIPELINE-SCAN INFO: Writing Raw JSON Results to file '/home/runner/work/veracode/veracode/results.json'. [05 Mar 2024 11:52:43,0636] PIPELINE-SCAN INFO: Writing Filtered JSON Results to file '/home/runner/work/veracode/veracode/filtered_results.json'. Scan Summary: PIPELINE_SCAN_VERSION: 23.11.0-0 DEV-STAGE: DEVELOPMENT SCAN_ID: 0f88d97d-32ab-411f-aaa9-fd8add7a38a8 SCAN_STATUS: SUCCESS SCAN_MESSAGE: Scan successful. Results size: 12897 bytes ==================== Analysis Successful. ==================== ========================== Found 1 Scannable modules. ========================== JS files within veracode.zip =================== Analyzed 1 modules. =================== JS files within veracode.zip ================== Analyzed 7 issues. ================== -------------------------------- Found 1 issues of High severity. -------------------------------- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'): src/sandbox/SnowflakeMock.ts:52 ------------------------------------- Skipping 4 issues of Medium severity. ------------------------------------- ---------------------------------- Skipping 2 issues of Low severity. ---------------------------------- ======================== FAILURE: Found 1 issues! ========================
register / create_check_run
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: octokit/[email protected], actions/upload-artifact@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
build / build-source-code-scan / build
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, actions/upload-artifact@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
pipeline_scan / pipeline scan
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, actions/download-artifact@v3, veracode/[email protected]. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.

Artifacts

Produced during runtime
Name Size
Veracode Pipeline-Scan Results Expired
18.5 KB
veracode-artifact Expired
4.08 MB
workflow-metadata Expired
126 Bytes