FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Update shiftleft.yml by shiftleft-chuck · Pull Request #19 · shiftleft-chuck/shiftleft-java-demo · GitHub

Update shiftleft.yml - #19

Open
shiftleft-chuck wants to merge 3 commits into
shiftleft-chuck-patch-9from
shiftleft-chuck-patch-10
Open

Update shiftleft.yml#19
shiftleft-chuck wants to merge 3 commits into
shiftleft-chuck-patch-9from
shiftleft-chuck-patch-10

Conversation

Copy link
Copy Markdown
Owner

No description provided.

Copy link
Copy Markdown

Checking analysis of application shiftleft-java-demo-220411 against 1 build rules.

querying scans/check: API returned status 404, with code: 'SCAN_NOT_FOUND' message: 'The specified scan was not found'.

Copy link
Copy Markdown

Neither source branch nor scan specified; switching to 'single' mode.

Checking analysis of application shiftleft-java-demo-220411 against 1 build rules.

Checking findings on scan 4.

Results per rule:

  • allow-zero-findings: FAIL (185 matched vulnerabilities; configured threshold is 0)

    First 5 findings:

    ID Severity Title
    70 critical pkg:maven/org.springframework.boot/spring-boot-starter-web@1.5.1.RELEASE
    71 critical pkg:maven/org.springframework.boot/spring-boot-starter-web@1.5.1.RELEASE
    72 critical pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE
    73 critical pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE
    78 critical pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    Severity Count
    Critical 52
    Moderate 92
    Info 41
    Finding Type Count
    Vuln 60
    Secret 0
    Insight 0
    Extscan 0
    Oss_vuln 125
    Package 0
    OWASP Category Count
    A3-Sensitive-Data-Exposure 41
    A3-Cross-Site-Scripting 9
    A1-Injection 4
    A5-Broken-Access-Control 3
    A8-Deserialization 2
    A2-Broken-Authentication 1
    Category Count
    Sensitive Data Usage 39
    XSS 9
    Directory Traversal 3
    Header Injection 3
    Security Best Practices 2
    Deserialization 2
    Remote Code Execution 1
    Session Injection 1

1 rule failed.

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant


Back | FazBrowse Home | New Git URL