This repository has been archived by the owner on Oct 2, 2024. It is now read-only.
Static Code Analysis - volur-v1-backend #31
Triggered via repository dispatch
March 5, 2024 11:51
veracode-workflow-app[bot]
source-code-pipeline-scan
11e101e
Status
Failure
Total duration
1m 33s
Artifacts
3
veracode-code-analysis.yml
on: repository_dispatch
register
/
create_check_run
3s
build
/
...
/
build
5s
build
/
...
/
build
build
/
...
/
build
build
/
...
/
build
build
/
...
/
build
pipeline_scan
/
pipeline scan
1m 3s
policy_scan
/
policy scan
Annotations
1 error and 3 warnings
pipeline_scan / pipeline scan
[05 Mar 2024 11:51:54,0865] PIPELINE-SCAN INFO: Pipeline Scan Tool Version 23.11.0-0.
[05 Mar 2024 11:51:54,0874] PIPELINE-SCAN INFO: Getting resource policy Veracode Recommended Medium + SCA
[05 Mar 2024 11:51:54,0905] PIPELINE-SCAN INFO: Successfully retrieved the policy
[05 Mar 2024 11:51:54,0905] PIPELINE-SCAN INFO: Policy name: Veracode Recommended Medium + SCA
[05 Mar 2024 11:51:54,0906] PIPELINE-SCAN INFO: CWE filter:
[05 Mar 2024 11:51:54,0906] PIPELINE-SCAN INFO: Severity filter: 4, 5,
[05 Mar 2024 11:51:54,0907] PIPELINE-SCAN INFO: Beginning scanning of './veracode_artifact_directory/veracode.zip'.
[05 Mar 2024 11:51:54,0908] PIPELINE-SCAN INFO: Sending 4273391 bytes to the server for analysis.
[05 Mar 2024 11:52:01,0454] PIPELINE-SCAN INFO: Upload complete.
[05 Mar 2024 11:52:01,0454] PIPELINE-SCAN INFO: Scan ID: 0f88d97d-32ab-411f-aaa9-fd8add7a38a8
[05 Mar 2024 11:52:02,0197] PIPELINE-SCAN INFO: Analysis Started.
===========================
Found 1 Scannable modules.
===========================
JS files within veracode.zip
[05 Mar 2024 11:52:43,0616] PIPELINE-SCAN INFO: Analysis Complete.
[05 Mar 2024 11:52:43,0627] PIPELINE-SCAN INFO: Analysis Results: Received 13425 bytes in 48720ms.
[05 Mar 2024 11:52:43,0632] PIPELINE-SCAN INFO: Writing Raw JSON Results to file '/home/runner/work/veracode/veracode/results.json'.
[05 Mar 2024 11:52:43,0636] PIPELINE-SCAN INFO: Writing Filtered JSON Results to file '/home/runner/work/veracode/veracode/filtered_results.json'.
Scan Summary:
PIPELINE_SCAN_VERSION: 23.11.0-0
DEV-STAGE: DEVELOPMENT
SCAN_ID: 0f88d97d-32ab-411f-aaa9-fd8add7a38a8
SCAN_STATUS: SUCCESS
SCAN_MESSAGE: Scan successful. Results size: 12897 bytes
====================
Analysis Successful.
====================
==========================
Found 1 Scannable modules.
==========================
JS files within veracode.zip
===================
Analyzed 1 modules.
===================
JS files within veracode.zip
==================
Analyzed 7 issues.
==================
--------------------------------
Found 1 issues of High severity.
--------------------------------
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'): src/sandbox/SnowflakeMock.ts:52
-------------------------------------
Skipping 4 issues of Medium severity.
-------------------------------------
----------------------------------
Skipping 2 issues of Low severity.
----------------------------------
========================
FAILURE: Found 1 issues!
========================
|
register / create_check_run
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: octokit/[email protected], actions/upload-artifact@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
build / build-source-code-scan / build
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, actions/upload-artifact@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
pipeline_scan / pipeline scan
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, actions/download-artifact@v3, veracode/[email protected]. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
Artifacts
Produced during runtime
Name | Size | |
---|---|---|
Veracode Pipeline-Scan Results
Expired
|
18.5 KB |
|
veracode-artifact
Expired
|
4.08 MB |
|
workflow-metadata
Expired
|
126 Bytes |
|