Skip to content

Update shiftleft.yml #32

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

Neither source branch nor scan specified; switching to 'single' mode.

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-java-demo against 2 build rules.

Using sl version 0.9.1252 (ec00b27f39489e6f4de4ecb5fc6450f299de038c).

Checking findings on scan 13.

Results per rule:

  • allow-zero-findings: FAIL (185 matched vulnerabilities; configured threshold is 0)

    First 5 findings:

    ID Severity CVE Title
    70 critical CVE-2018-1196 pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE
    71 critical CVE-2017-8046 pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE
    76 critical CVE-2019-10072 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    77 critical CVE-2018-11784 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    78 critical CVE-2019-12418 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    Severity Count
    Critical 52
    Moderate 92
    Info 41
    Finding Type Count
    Vuln 60
    Secret 0
    Insight 0
    Extscan 0
    Oss_vuln 125
    Container 0
    Package 0
    Category Count
    Sensitive Data Usage 39
    Cross-Site Scripting 9
    Header Injection 3
    Directory Traversal 3
    Security Best Practices 2
    Deserialization 2
    Session Injection 1
    Remote Code Execution 1
    OWASP Category Count
    A3-Sensitive-Data-Exposure 41
    A3-Cross-Site-Scripting 9
    A1-Injection 4
    A5-Broken-Access-Control 3
    A8-Deserialization 2
    A2-Broken-Authentication 1
  • reachable-oss-vuln: FAIL ( 46 matched vulnerabilities; configured threshold is 0)

    First 10 findings:

    ID Severity CVE Title
    76 critical CVE-2019-10072 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    77 critical CVE-2018-11784 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    78 critical CVE-2019-12418 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    79 critical CVE-2018-8034 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    80 critical CVE-2019-17563 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    81 critical CVE-2018-1305 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    82 critical CVE-2018-8037 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    83 critical CVE-2020-17527 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    84 critical CVE-2019-0199 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    85 critical CVE-2020-1935 pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11
    Severity Count
    Critical 40
    Moderate 6
    Info 0

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant