Running with gitlab-runner 17.1.0 (fe451d5a)  on osm-cicd-10 S9P1hQmo, system ID: s_0c544012072a Resolving secrets section_start:1738591089:prepare_executor Preparing the "docker" executor Using Docker executor with image registry.gitlab.com/security-products/semgrep:5 ... Pulling docker image registry.gitlab.com/security-products/semgrep:5 ... Using docker image sha256:966b9dbd58307eb69533ef24a2de3cf8bf7c4508d54d7bca5bee104d2e4e417a for registry.gitlab.com/security-products/semgrep:5 with digest registry.gitlab.com/security-products/semgrep@sha256:24c1e65bbbf84e7b6b3f16d956dcc54d992b81749cdaf3c41bdfce6209b92857 ... section_end:1738591092:prepare_executor section_start:1738591092:prepare_script Preparing environment Running on runner-s9p1hqmo-project-75-concurrent-1 via osm-cicd-10... section_end:1738591093:prepare_script section_start:1738591093:get_sources Getting source from Git repository Fetching changes with git depth set to 50... Initialized empty Git repository in /builds/gitlab/osm/tests/.git/ Created fresh repository. Checking out 8a6e4200 as detached HEAD (ref is v14.0)... Skipping Git submodules setup section_end:1738591095:get_sources section_start:1738591095:step_script Executing "step_script" stage of the job script Using docker image sha256:966b9dbd58307eb69533ef24a2de3cf8bf7c4508d54d7bca5bee104d2e4e417a for registry.gitlab.com/security-products/semgrep:5 with digest registry.gitlab.com/security-products/semgrep@sha256:24c1e65bbbf84e7b6b3f16d956dcc54d992b81749cdaf3c41bdfce6209b92857 ... $ /analyzer run [DEBUG] ▶ Choosing the input analyzer report: '/builds/gitlab/osm/tests/gl-sast-report.json' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/command.go:79] ▶ GitLab Semgrep analyzer v5.26.1 [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ ANALYZER_TARGET_DIR,CI_PROJECT_DIR=/builds/gitlab/osm/tests [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ ANALYZER_ARTIFACT_DIR,CI_PROJECT_DIR=/builds/gitlab/osm/tests [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ ANALYZER_INDENT_REPORT=false [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ ANALYZER_OPTIMIZE_REPORT=true [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ ADDITIONAL_CA_CERT_BUNDLE= [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SEARCH_IGNORED_DIRS=bundle,node_modules,vendor,tmp,test,tests [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SEARCH_IGNORE_HIDDEN_DIRS=true [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SEARCH_MAX_DEPTH=20 [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SAST_SEMGREP_METRICS=true [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SAST_EXPERIMENTAL_FEATURES=false [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SAST_EXCLUDED_PATHS=spec, test, tests, tmp [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SAST_SCANNER_ALLOWED_CLI_OPTS= [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:267] ▶ SAST_EXCLUDED_PATHS=spec,test,tests,tmp [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/common/v3@v3.4.0/cacert/cacert.go:65] ▶ CA cert bundle not imported: empty bundle or empty target path [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:131] ▶ Detecting project [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/plugin/plugin.go:40] ▶ could not check for semgrep rules in the custom ruleset, choosing language-based matching filter as a fallback [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:153] ▶ Analyzer will attempt to analyze all projects in the repository [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:165] ▶ Loading ruleset for /builds/gitlab/osm/tests [WARN] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/ruleset/v3@v3.3.1/ruleset.go:263] ▶ /builds/gitlab/osm/tests/.gitlab/sast-ruleset.toml not found, ruleset customization will be disabled. [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:175] ▶ Running analyzer [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/gitlab/LICENSE [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/lgpl/LICENSE [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/lgpl-cc/LICENSE [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/manifest.json [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:214] ▶ 19 active rule files detected with 587 active rules [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/bandit.yml': '1d5f1383c92f36acb1d037009fe18a1f2b23e018a4b4cf6d62f779876bf4954d' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/eslint.yml': '9a0000468fb7788df7a1f0dcedab6b52f63f48bb20e23be1703d09df4f26a43d' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/find_sec_bugs.yml': '4ffaf454577a0f2570a5923eb626c5ad5cc2acb61ba69f195133446bb13ce016' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/find_sec_bugs_scala.yml': '511d1fcd1844c8c598ce2eecacf95ab876bfadb01c7740d474d007250f033a97' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/flawfinder.yml': 'c03d70d0acaf5d6f42173b0141fd1ac40fb2a61b2d9e6867d6785b56f366bf90' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/gitlab/gitlab_ee_java.yml': '4447e55e10167e94a8e720d2b4c0b468de341261c3416fd32ceb63ba15bff134' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/gitlab/gitlab_ee_javascript.yml': '428c386226edb09210df0df08ca4c2464949e948a88045694b3cfaab8079b8dc' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/gitlab_ce_python.yml': 'a1adf6cde5fa7e8ef530bd3ec122f6ac827e989f2c862aeae28a58a69c78ab6b' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/gitlab_ce_scala.yml': 'ee3d5ba84846f6c94085a1a76d3d250e68ce9c7f7502003647f7125a8667e1a3' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/gosec.yml': '2f8a4f954c8358ed4b5529be4f557190090209df1ac67bf55d24af2d755ffca0' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl-cc/brakeman.yml': '27bfe7c3e464b2786c360004c50a8e487c46f9ea7ffe011b5190696224665301' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl-cc/gitlab_lgpl_cc_java.yml': '17d681aba56265d68cbeb7e90681f2d69d8c0440714acb4940b57e9b5cb67bbb' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl-cc/gitlab_lgpl_cc_javascript.yml': 'abf15ac30a8c820f2d192a812d48f3a76e805c1cd3bee91d3b19d7c09d482519' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl-cc/gitlab_lgpl_cc_python.yml': '4fcb59e05b1bdb418ab3ce009b0af0c565fe16d255013f9f65e1981734fafbe8' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl-cc/phpcs_security_audit.yml': '7f3448e2fdbca069c55c5f34971fc48382ec1af86a973ee24614ce320494d630' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl/find_sec_bugs_kotlin.yml': '46cdf5ab58a11576cb48f87c42e587f21136e01b33b352d7444e8c74e5ae446f' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl/mobsf.yml': '18c9f0273caf79503e75cfdff7efa38fdec4a9e5f3084ebb915fe492a3446f66' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/lgpl/nodejs_scan.yml': 'f278351679f6874078ce4fd6a04b103936e944fd82936a919632d3cba2110ca8' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:220] ▶ * rule file '/rules/security_code_scan.yml': 'a145b41abb93f352f70e9e7b7c335d09d0e1a95298f7fed85e35ef2fd3d7e4e8' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:222] ▶ Combined rule checksum: '50cd48f2f6b045e313e5070f3e04df87c8aa93267e2f8a24321f7ba202745e1d' [INFO] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/rules/ruleinfo.go:232] ▶ Using the GitLab SAST default ruleset [DEBU] [Semgrep] [2025-02-03T13:58:16Z] [/go/src/buildapp/analyze.go:100] ▶ /usr/local/bin/semgrep -f /rules -o /builds/gitlab/osm/tests/semgrep.sarif --sarif --no-rewrite-rule-ids --strict --disable-version-check --no-git-ignore --exclude spec --exclude test --exclude tests --exclude tmp --metrics on --verbose [INFO] [Semgrep] [2025-02-03T13:58:19Z] ▶ METRICS: Using configs from the Registry (like --config=p/ci) reports pseudonymous rule metrics to semgrep.dev. [INFO] [Semgrep] [2025-02-03T13:58:19Z] ▶ To disable Registry rule metrics, use "--metrics=off". [INFO] [Semgrep] [2025-02-03T13:58:19Z] ▶ Using configs only from local files (like --config=xyz.yml) does not enable metrics. [INFO] [Semgrep] [2025-02-03T13:58:19Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:19Z] ▶ More information: https://semgrep.dev/docs/metrics [INFO] [Semgrep] [2025-02-03T13:58:19Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ running 587 rules from 19 configs [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ Using explicit semgrepignore file from environment variable [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ Rules: [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B101 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B102 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B103 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B104 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B108 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B113 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B201 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B202 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B301-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B301-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B301-3 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B301-4 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B302 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B303-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B303-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B303-7 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B303-8 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-10 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-11 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-12 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-3 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-4 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-5 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-6 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-7 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-8 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B304-9 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B305 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B306 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B307 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B310-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B311 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B313 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B314 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B315 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B316 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B317 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B318 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B319 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B320 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B323 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B324 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B401 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B413 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B501 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B502 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B504 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B505-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B505-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B506 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B507 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B508 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B509 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B602 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B603 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B604 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B605 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B606 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B607 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B608 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B609 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B610 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B611-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B611-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B612 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B701 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B702 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - bandit.B703 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_cookie_rule-CheckCookieStoreSessionSecurityAttributes [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_cookie_rule-CookieSerialization [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_crypto_rule-InsufficientRSAKeySize [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_crypto_rule-WeakHashesMD5 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_crypto_rule-WeakHashesSHA1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_csrf_rule-MissingCSRFProtection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_deserialization_rule-BadDeserialization [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_deserialization_rule-BadDeserializationEnv [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_deserialization_rule-BadDeserializationYAML [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_error_rule-DivideByZero [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_escaping_rule-JSONEntityEscape [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_eval_rule-NoEval [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_exceptions_rule-DetailedExceptions [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_file_rule-AvoidTaintedFileAccess [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_file_rule-CheckRenderLocalFileInclude [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_file_rule-CheckSendFile [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_filter_rule-CheckBeforeFilter [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_find_rule-CheckUnscopedFind [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_ftp_rule-AvoidTaintedFTPCall [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_http_rule-AvoidTaintedHTTPRequest [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_http_rule-CheckHTTPVerbConfusion [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_injection_rule-AvoidTaintedShellCall [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_injection_rule-BadSend [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_injection_rule-DangerousExec [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_mass_assignment_rule-ModelAttrAccessible [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_mass_assignment_rule-UnprotectedMassAssign [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_redirect_rule-CheckRedirectTo [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_reflection_rule-CheckUnsafeReflection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_reflection_rule-CheckUnsafeReflectionMethods [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_regex_rule-CheckRegexDOS [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_regex_rule-CheckValidationRegex [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_routes_rule-AvoidDefaultRoutes [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_session_rule-AvoidSessionManipulation [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_sql_rule-CheckSQL [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_ssl_rule-ForceSSLFalse [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_ssl_rule-SSLModeNoVerify [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_xss_rule-AvoidLinkTo [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_xss_rule-AvoidRenderInline [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_xss_rule-AvoidRenderText [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - brakeman.ruby_xss_rule-ManualTemplateCreation [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-buffer-noassert [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-disable-mustache-escape [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-eval-with-expression [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-new-buffer [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-non-literal-fs-filename [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-non-literal-regexp [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-non-literal-require [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-possible-timing-attacks [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.detect-pseudoRandomBytes [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - eslint.react-dangerouslysetinnerhtml [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.BAD_HEXA_CONVERSION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.BLOWFISH_KEY_SIZE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.CIPHER_INTEGRITY-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.COMMAND_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.CUSTOM_MESSAGE_DIGEST-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.DANGEROUS_PERMISSION_COMBINATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.DEFAULT_HTTP_CLIENT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.DES_USAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.DMI_CONSTANT_DB_PASSWORD-1.HARD_CODE_PASSWORD-3 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.DMI_EMPTY_DB_PASSWORD-1.HARD_CODE_PASSWORD-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.ECB_MODE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.EL_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.EXTERNAL_CONFIG_CONTROL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.FILE_UPLOAD_FILENAME-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.FORMAT_STRING_MANIPULATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.HARD_CODE_PASSWORD-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.HAZELCAST_SYMMETRIC_ENCRYPTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.HRS_REQUEST_PARAMETER_TO_HTTP_HEADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.HTTP_PARAMETER_POLLUTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.HTTP_RESPONSE_SPLITTING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.INSECURE_COOKIE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.INSECURE_SMTP_SSL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.LDAP_ANONYMOUS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.LDAP_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.MALICIOUS_XSLT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.MODIFICATION_AFTER_VALIDATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.NORMALIZATION_AFTER_VALIDATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.NULL_CIPHER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.OGNL_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.OVERLY_PERMISSIVE_FILE_PERMISSION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.PADDING_ORACLE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.PERMISSIVE_CORS-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.PT_ABSOLUTE_PATH_TRAVERSAL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.REQUESTDISPATCHER_FILE_DISCLOSURE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.RSA_KEY_SIZE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.RSA_NO_PADDING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.SAML_IGNORE_COMMENTS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.SCRIPT_ENGINE_INJECTION-1.SPEL_INJECTION-1.EL_INJECTION-2.SEAM_LOG_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.SCRIPT_ENGINE_INJECTION-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.SMTP_HEADER_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.SPRING_FILE_DISCLOSURE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.SSL_CONTEXT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.SSL_CONTEXT-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.TDES_USAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.TEMPLATE_INJECTION_PEBBLE-1.TEMPLATE_INJECTION_FREEMARKER-1.TEMPLATE_INJECTION_VELOCITY-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.UNVALIDATED_REDIRECT-1.URL_REWRITING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.URLCONNECTION_SSRF_FD-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.WEAK_FILENAMEUTILS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.WEAK_HOSTNAME_VERIFIER [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.WEAK_MESSAGE_DIGEST_MD5-1.WEAK_MESSAGE_DIGEST_SHA1-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.WEAK_TRUST_MANAGER [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.WICKET_XSS1-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.XML_DECODER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.XSS_REQUEST_PARAMETER_TO_SERVLET_WRITER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs.XXE_XMLREADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.BAD_HEXA_CONVERSION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.BLOWFISH_KEY_SIZE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.CIPHER_INTEGRITY-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.COMMAND_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.CUSTOM_MESSAGE_DIGEST-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.DANGEROUS_PERMISSION_COMBINATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.DES_USAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.DMI_CONSTANT_DB_PASSWORD-1.HARD_CODE_PASSWORD-3 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.DMI_EMPTY_DB_PASSWORD-1.HARD_CODE_PASSWORD-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.ECB_MODE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.EL_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.EXTERNAL_CONFIG_CONTROL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.FILE_UPLOAD_FILENAME-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.FORMAT_STRING_MANIPULATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.HARD_CODE_PASSWORD-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.HAZELCAST_SYMMETRIC_ENCRYPTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.HRS_REQUEST_PARAMETER_TO_HTTP_HEADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.HTTPONLY_COOKIE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.HTTP_PARAMETER_POLLUTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.HTTP_RESPONSE_SPLITTING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.INSECURE_COOKIE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.INSECURE_SMTP_SSL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.LDAP_ANONYMOUS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.LDAP_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.MALICIOUS_XSLT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.MODIFICATION_AFTER_VALIDATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.NORMALIZATION_AFTER_VALIDATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.NULL_CIPHER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.OGNL_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.OVERLY_PERMISSIVE_FILE_PERMISSION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.PADDING_ORACLE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.PERMISSIVE_CORS-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.PT_ABSOLUTE_PATH_TRAVERSAL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.REQUESTDISPATCHER_FILE_DISCLOSURE-1.STRUTS_FILE_DISCLOSURE-1.SPRING_FILE_DISCLOSURE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.RSA_KEY_SIZE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.RSA_NO_PADDING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.SAML_IGNORE_COMMENTS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.SCRIPT_ENGINE_INJECTION-1.SPEL_INJECTION-1.EL_INJECTION-2.SEAM_LOG_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.SMTP_HEADER_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.SPRING_CSRF_PROTECTION_DISABLED-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.SQL_INJECTION_SPRING_JDBC-1.SQL_INJECTION_JPA-1.SQL_INJECTION_JDO-1.SQL_INJECTION_JDBC-1.SQL_NONCONSTANT_STRING_PASSED_TO_EXECUTE-1.SQL_INJECTION-1.SQL_INJECTION_HIBERNATE-1.SQL_INJECTION_VERTX-1.SQL_PREPARED_STATEMENT_GENERATED_FROM_NONCONSTANT_STRING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.SSL_CONTEXT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.SSL_CONTEXT-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.TDES_USAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.TEMPLATE_INJECTION_PEBBLE-1.TEMPLATE_INJECTION_FREEMARKER-1.TEMPLATE_INJECTION_VELOCITY-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.UNVALIDATED_REDIRECT-1.URL_REWRITING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.URLCONNECTION_SSRF_FD-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.WEAK_FILENAMEUTILS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.WEAK_HOSTNAME_VERIFIER-1.WEAK_TRUST_MANAGER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.WEAK_MESSAGE_DIGEST_MD5-1.WEAK_MESSAGE_DIGEST_SHA1-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.WICKET_XSS1-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.XML_DECODER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.XPATH_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.XSS_REQUEST_PARAMETER_TO_SERVLET_WRITER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.XXE_SAXPARSER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.XXE_XMLREADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_kotlin.XXE_XMLSTREAMREADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.AWS_QUERY_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.BAD_HEXA_CONVERSION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.BEAN_PROPERTY_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.BLOWFISH_KEY_SIZE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.CIPHER_INTEGRITY-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.COMMAND_INJECTION-1.SCALA_COMMAND_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.COOKIE_PERSISTENT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.COOKIE_USAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.CRLF_INJECTION_LOGS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.CUSTOM_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.CUSTOM_INJECTION-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.CUSTOM_MESSAGE_DIGEST-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.DANGEROUS_PERMISSION_COMBINATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.DEFAULT_HTTP_CLIENT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.DES_USAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.DMI_CONSTANT_DB_PASSWORD-1.HARD_CODE_PASSWORD-3 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.DMI_EMPTY_DB_PASSWORD-1.HARD_CODE_PASSWORD-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.ECB_MODE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.EL_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.EXTERNAL_CONFIG_CONTROL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.FILE_UPLOAD_FILENAME-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.FORMAT_STRING_MANIPULATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.HARD_CODE_PASSWORD-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.HAZELCAST_SYMMETRIC_ENCRYPTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.HRS_REQUEST_PARAMETER_TO_COOKIE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.HRS_REQUEST_PARAMETER_TO_HTTP_HEADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.HTTPONLY_COOKIE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.HTTP_PARAMETER_POLLUTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.HTTP_RESPONSE_SPLITTING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.IMPROPER_UNICODE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.INFORMATION_EXPOSURE_THROUGH_AN_ERROR_MESSAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.INSECURE_COOKIE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.INSECURE_SMTP_SSL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.JAXRS_ENDPOINT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.JAXWS_ENDPOINT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.LDAP_ANONYMOUS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.LDAP_ENTRY_POISONING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.LDAP_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.MALICIOUS_XSLT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.MODIFICATION_AFTER_VALIDATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.NORMALIZATION_AFTER_VALIDATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.NULL_CIPHER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.OGNL_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.OVERLY_PERMISSIVE_FILE_PERMISSION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.OVERLY_PERMISSIVE_FILE_PERMISSION-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.PADDING_ORACLE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.PATH_TRAVERSAL_IN-1.SCALA_PATH_TRAVERSAL_IN-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.PATH_TRAVERSAL_OUT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.PERMISSIVE_CORS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.PERMISSIVE_CORS-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.PT_ABSOLUTE_PATH_TRAVERSAL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.PT_RELATIVE_PATH_TRAVERSAL-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.REQUESTDISPATCHER_FILE_DISCLOSURE-1.STRUTS_FILE_DISCLOSURE-1.SPRING_FILE_DISCLOSURE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.RPC_ENABLED_EXTENSIONS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.RSA_KEY_SIZE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.RSA_NO_PADDING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SAML_IGNORE_COMMENTS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SCALA_PLAY_SSRF-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SCALA_SENSITIVE_DATA_EXPOSURE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SCALA_XSS_MVC_API-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SCRIPT_ENGINE_INJECTION-1.SPEL_INJECTION-1.EL_INJECTION-2.SEAM_LOG_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SCRIPT_ENGINE_INJECTION-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SMTP_HEADER_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SQL_INJECTION_SPRING_JDBC-1.SQL_INJECTION_JPA-1.SQL_INJECTION_JDO-1.SQL_INJECTION_JDBC-1.SQL_NONCONSTANT_STRING_PASSED_TO_EXECUTE-1.SCALA_SQL_INJECTION_SLICK-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.SSL_CONTEXT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.STRUTS_FORM_VALIDATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.TDES_USAGE-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.TEMPLATE_INJECTION_PEBBLE-1.TEMPLATE_INJECTION_FREEMARKER-1.TEMPLATE_INJECTION_VELOCITY-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.TRUST_BOUNDARY_VIOLATION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.UNENCRYPTED_SOCKET-1.UNENCRYPTED_SERVER_SOCKET-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.UNVALIDATED_REDIRECT-1.URL_REWRITING-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.URLCONNECTION_SSRF_FD-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.WEAK_FILENAMEUTILS-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.WEAK_HOSTNAME_VERIFIER-1.WEAK_TRUST_MANAGER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.WEAK_MESSAGE_DIGEST_MD5-1.WEAK_MESSAGE_DIGEST_SHA1-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.WICKET_XSS1-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XML_DECODER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XPATH_INJECTION-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XSS_REQUEST_PARAMETER_TO_SERVLET_WRITER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XSS_REQUEST_WRAPPER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XSS_SERVLET-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XXE_DOCUMENT-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XXE_DTD_TRANSFORM_FACTORY-1.XXE_XSLT_TRANSFORM_FACTORY-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XXE_SAXPARSER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XXE_XMLREADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XXE_XMLSTREAMREADER-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - find_sec_bugs_scala.XXE_XPATH-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.AddAccessAllowedAce-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.CreateProcess-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.CreateProcessAsUser-1.CreateProcessWithLogon-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.EVP_des_ecb-1.EVP_des_cbc-1.EVP_des_cfb-1.EVP_des_ofb-1.EVP_desx_cbc-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.EVP_rc4_40-1.EVP_rc2_40_cbc-1.EVP_rc2_64_cbc-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.GetTempFileName-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.LoadLibrary-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.LoadLibraryEx-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.MultiByteToWideChar-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.RpcImpersonateClient-1.ImpersonateLoggedOnUser-1.CoImpersonateClient-1.ImpersonateNamedPipeClient-1.ImpersonateDdeClientWindow-1.ImpersonateSecurityContext-1.SetThreadToken-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.SetSecurityDescriptorDacl-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.StrCat-1.StrCatA-1.StrcatW-1.lstrcatA-1.lstrcatW-1.strCatBuff-1.StrCatBuffA-1.StrCatBuffW-1.StrCatChainW-1._tccat-1._mbccat-1._ftcscat-1.StrCatN-1.StrCatNA-1.StrCatNW-1.StrNCat-1.StrNCatA-1.StrNCatW-1.lstrncat-1.lstrcatnA-1.lstrcatnW-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.access-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.atoi-1.atol-1._wtoi-1._wtoi64-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.chmod-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.chown-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.crypt-1.crypt_r-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.cuserid-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.drand48-1.erand48-1.jrand48-1.lcong48-1.lrand48-1.mrand48-1.nrand48-1.random-1.seed48-1.setstate-1.srand-1.strfry-1.srandom-1.g_rand_boolean-1.g_rand_int-1.g_rand_int_range-1.g_rand_double-1.g_rand_double_range-1.g_random_boolean-1.g_random_int-1.g_random_int_range-1.g_random_double-1.g_random_double_range-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.execl-1.execlp-1.execle-1.execv-1.execvp-1.popen-1.WinExec-1.ShellExecute-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.fopen-1.open-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.fprintf-1.vfprintf-1._ftprintf-1._vftprintf-1.fwprintf-1.fvwprintf-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.fscanf-1.sscanf-1.vsscanf-1.vfscanf-1._ftscanf-1.fwscanf-1.vfwscanf-1.vswscanf-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.g_get_home_dir-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.g_get_tmp_dir-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.getenv-1.curl_getenv-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.getlogin-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.getpass-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.gets-1._getts-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.getwd-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.gsignal-1.ssignal-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.lstrcat-1.wcscat-1._tcscat-1._mbscat-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.lstrcatn-1.wcsncat-1._tcsncat-1._mbsnbcat-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.lstrcpy-1.wcscpy-1._tcscpy-1._mbscpy-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.lstrcpyn-1.wcsncpy-1._tcsncpy-1._mbsnbcpy-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.memalign-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.memcpy-1.CopyMemory-1.bcopy-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.mkstemp-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.mktemp-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.printf-1.vprintf-1.vwprintf-1.vfwprintf-1._vtprintf-1.wprintf-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.readlink-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.realpath-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.scanf-1.vscanf-1.wscanf-1._tscanf-1.vwscanf-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.snprintf-1.vsnprintf-1._snprintf-1._sntprintf-1._vsntprintf-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.sprintf-1.vsprintf-1.swprintf-1.vswprintf-1._stprintf-1._vstprintf-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strcat-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strccpy-1.strcadd-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strcpy-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strcpyA-1.strcpyW-1.StrCpy-1.StrCpyA-1.lstrcpyA-1.lstrcpyW-1._tccpy-1._mbccpy-1._ftcscpy-1._mbsncpy-1.StrCpyN-1.StrCpyNA-1.StrCpyNW-1.StrNCpy-1.strcpynA-1.StrNCpyA-1.StrNCpyW-1.lstrcpynA-1.lstrcpynW-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.streadd-1.strecpy-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strlen-1.wcslen-1._tcslen-1._mbslen-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strncat-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strncpy-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.strtrns-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.syslog-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.system-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.tmpfile-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.tmpnam-1.tempnam-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.ulimit-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.umask-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.usleep-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - flawfinder.vfork-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G102-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G103-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G106-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G107-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G108-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G109-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G110-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G111-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G114-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G202-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G203-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G204-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G301-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G302-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G303-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G304-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G305-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G306-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G402-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G402-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G403-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G404-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G501-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G502-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G503-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G505-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - gosec.G601-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_cookie_rule-CookieHTTPOnly [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-DisallowOldTLSVersion [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-GCMNonceReuse [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-HTTPUrlConnectionHTTPRequest [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-HttpComponentsRequest [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-HttpGetHTTPRequest [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-SocketRequestUnsafeProtocols [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-SpringFTPRequest [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-SpringHTTPRequestRestTemplate [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-TLSUnsafeRenegotiation [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-TelnetRequest [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-UnirestHTTPRequest [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-UseOfRC2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule-UseOfRC4 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule_JwtDecodeWithoutVerify [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_crypto_rule_JwtNoneAlgorithm [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_csrf_rule-SpringCSRFDisabled [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_csrf_rule-UnrestrictedRequestMapping [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_deserialization_rule-InsecureJmsDeserialization [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_deserialization_rule-JacksonUnsafeDeserialization [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_deserialization_rule-ServerDangerousObjectDeserialization [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_deserialization_rule-SnakeYamlConstructor [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_endpoint_rule-ManuallyConstructedURLs [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_file_rule-FilePathTraversalHttpServlet [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_ftp_rule-FTPInsecureTransport [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_inject_rule-DangerousGroovyShell [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_inject_rule-EnvInjection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_inject_rule-MongodbNoSQLi [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_inject_rule-SeamLogInjection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_inject_rule-SqlInjection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_traversal_rule-RelativePathTraversal [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xpathi_rule-XpathInjection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-DisallowDoctypeDeclFalse [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-DocumentBuilderFactoryDisallowDoctypeDeclMissing [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-ExternalGeneralEntitiesTrue [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-ExternalParameterEntitiesTrue [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-SAXParserFactoryDisallowDoctypeDeclMissing [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-TransformerfactoryDTDNotDisabled [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-XMLInputFactoryExternalEntitiesEnabled [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - java_xxe_rule-XMLStreamRdr [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - javascript_crypto_rule-NodeLibcurlSSLVerificationDisable [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - javascript_exec_rule-child-process [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.java-webview-rule-ignore_ssl_certificate_errors [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.java-webview-rule-webview_debugging [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.java-webview-rule-webview_external_storage [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.java-webview-rule-webview_set_allow_file_access [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.kotlin-webview-rule-android_kotlin_webview_debug [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.oc-other-rule-ios_self_signed_ssl [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.oc-other-rule-ios_webview_ignore_ssl [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.swift-other-rule-ios_biometric_acl [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.swift-other-rule-ios_dtls1_used [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.swift-other-rule-ios_file_no_special [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.swift-other-rule-ios_keychain_weak_accessibility_value [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - mobsf.swift-other-rule-ios_tls3_not_used [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_aes_ecb [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_aes_noiv [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_insecure_random_generator [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_md5 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_sha1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_timing_attack [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_tls_reject [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-crypto-rule-node_weak_crypto [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-database-rule-node_knex_sqli_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-database-rule-node_nosqli_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-database-rule-node_nosqli_js_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-database-rule-node_sqli_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-database-rule-sequelize_tls [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-database-rule-sequelize_tls_cert_validation [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-database-rule-sequelize_weak_tls [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-dos-rule-layer7_object_dos [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-dos-rule-regex_dos [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-electronjs-rule-electron_allow_http [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-electronjs-rule-electron_blink_integration [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-electronjs-rule-electron_context_isolation [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-electronjs-rule-electron_disable_websecurity [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-electronjs-rule-electron_experimental_features [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-electronjs-rule-electron_nodejs_integration [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-eval_nodejs [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-eval_require [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-grpc_insecure_connection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-node_deserialize [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-sandbox_code_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-serializetojs_deserialize [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-server_side_template_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-vm2_code_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-vm2_context_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-vm_code_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-vm_compilefunction_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-vm_runincontext_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-vm_runinnewcontext_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-eval-rule-yaml_deserialize [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-exec-rule-shelljs_os_command_exec [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-cookie_session_default [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-cookie_session_no_domain [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-cookie_session_no_httponly [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-cookie_session_no_maxage [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-cookie_session_no_path [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-cookie_session_no_samesite [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-cookie_session_no_secure [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-express_cors [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-generic_cors [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-generic_header_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-header_xss_generic [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-header_xss_lusca [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-helmet_feature_disabled [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-headers-rule-host_header_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-jwt-rule-hardcoded_jwt_secret [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-jwt-rule-jwt_exposed_credentials [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-jwt-rule-jwt_exposed_data [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-jwt-rule-jwt_express_hardcoded [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-jwt-rule-jwt_not_revoked [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-jwt-rule-node_jwt_none_algorithm [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-memory-rule-buffer_noassert [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-redirect-rule-express_open_redirect [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-redirect-rule-express_open_redirect2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-ssrf-rule-node_ssrf [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-ssrf-rule-phantom_ssrf [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-ssrf-rule-playwright_ssrf [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-ssrf-rule-puppeteer_ssrf [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-ssrf-rule-wkhtmltoimage_ssrf [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-ssrf-rule-wkhtmltopdf_ssrf [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-traversal-rule-admzip_path_overwrite [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-traversal-rule-express_lfr [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-traversal-rule-express_lfr_warning [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-traversal-rule-generic_path_traversal [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-traversal-rule-join_resolve_path_traversal [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-traversal-rule-tar_path_overwrite [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-traversal-rule-zip_path_overwrite [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xml-rule-node_entity_expansion [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xml-rule-node_xpath_injection [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xml-rule-node_xxe [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xml-rule-xxe_expat [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xss-rule-express_xss [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xss-rule-handlebars_noescape [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xss-rule-handlebars_safestring [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xss-rule-squirrelly_autoescape [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xss-rule-xss_disable_mustache_escape [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - nodejs_scan.javascript-xss-rule-xss_serialize_javascript [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.Asserts.WarnFunctionHandling [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.Backticks.WarnSystemExec [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.CryptoFunctions.WarnCryptoFunc-Mcrypt [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.CryptoFunctions.WarnCryptoFunc-WeakCrypto [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.FilesystemFunctions.WarnFilesystem [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.FringeFunctions.WarnFringestuff [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.NoEvals.NoEvals [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.Phpinfos.WarnPhpinfo [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - phpcs_security_audit.PHPCS_SecurityAudit.BadFunctions.SystemExecFunctions.WarnSystemExec [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_crypto_rule-HTTPConnectionPool [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_exec_rule-start-process-partial-path [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_exec_rule-start-process-path [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_exec_rule-subprocess-call-array [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_flask_rule-flask-open-redirect [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_flask_rule-flask-tainted-sql-string [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_flask_rule-path-traversal-open [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_jwt_rule-jwt-none-alg [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - python_pyramid_rule-pyramid-csrf-origin-check [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - scala_unsafe_rule-InformationExposureVariant2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0001-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0002-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0003-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0004-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0005-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0006-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0008-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0009-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0010-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0011-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0013-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0016-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0017-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0018-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0026-1.SCS0031-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0027-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0028-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0029-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0029-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0032-1.SCS0033-1.SCS0034-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0035-1 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ - security_code_scan.SCS0035-2 [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ Ignoring /builds/gitlab/osm/tests/.gitignore due to .semgrepignore [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ ┌─────────────┐ [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ │ Scan Status │ [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ └─────────────┘ [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ Scanning 137 files with 587 Code rules: [INFO] [Semgrep] [2025-02-03T13:58:26Z] ▶ Scanning 8 files with 79 python rules. [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ ======================================== [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Files skipped: [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ ======================================== [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Always skipped by Semgrep: [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/FETCH_HEAD [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/HEAD [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/config [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/index [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/logs/HEAD [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/logs/refs/remotes/origin/v14.0 [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/objects/pack/pack-0c4dbd7134e14161baac56a25a5e5e3db6ff1fb4.idx [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/objects/pack/pack-0c4dbd7134e14161baac56a25a5e5e3db6ff1fb4.pack [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/refs/pipelines/18163 [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/refs/remotes/origin/v14.0 [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/refs/tags/release-v14.0-start [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/refs/tags/v14.0.0 [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/refs/tags/v14.0.0rc1 [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/refs/tags/v14.0.1 [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/refs/tags/v14.0.2 [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .git/shallow [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Skipped by .gitignore: [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ (Disabled with --no-git-ignore) [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ •  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Skipped by .semgrepignore: [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ - https://semgrep.dev/docs/ignoring-files-folders-code/#understanding-semgrep-defaults [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ • .gitignore [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Skipped by --include patterns: [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ •  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Skipped by --exclude patterns: [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ •  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Skipped by limiting to files smaller than 1000000 bytes: [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ (Adjust with the --max-target-bytes flag) [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ •  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Partially analyzed due to parsing or internal Semgrep errors [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ •  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ ┌──────────────┐ [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ │ Scan Summary │ [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ └──────────────┘ [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Some files were skipped or only partially analyzed. [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Scan skipped: 1 files matching .semgrepignore patterns [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ For a full list of skipped files, run semgrep with the --verbose flag. [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶  [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Ran 79 rules on 8 files: 7 findings. [INFO] [Semgrep] [2025-02-03T13:58:31Z] ▶ Sending pseudonymous metrics since metrics are configured to ON and registry usage is False [INFO] [Semgrep] [2025-02-03T13:58:32Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/run.go:189] ▶ Creating report [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/src/buildapp/convert.go:43] ▶ Converting report with the root path: /builds/gitlab/osm/tests [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/gitlab/LICENSE [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/lgpl/LICENSE [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/lgpl-cc/LICENSE [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/src/buildapp/rules/ruleinfo.go:307] ▶ skipping parse for non-rule file: /rules/manifest.json [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/report/v5@v5.6.0/report.go:214] ▶ No Ids found to disable [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/report/v5@v5.6.0/report.go:256] ▶ Applying report overrides [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/report/v5@v5.6.0/report.go:275] ▶ No Ids found to override [DEBU] [Semgrep] [2025-02-03T13:58:32Z] [/go/pkg/mod/gitlab.com/gitlab-org/security-products/analyzers/command/v3@v3.1.0/jsonout.go:54] ▶ Optimizing JSON Output [INFO] [2025-02-03T13:58:32Z] [/build/clicmds/query.go:89] ▶ /builds/gitlab/osm/tests/gl-report-post.json written section_end:1738591112:step_script section_start:1738591112:upload_artifacts_on_success Uploading artifacts for successful job Uploading artifacts... gl-sast-report.json: found 1 matching artifact files and directories Uploading artifacts as "sast" to coordinator... 201 Created id=108519 responseStatus=201 Created token=glcbt-64 section_end:1738591113:upload_artifacts_on_success section_start:1738591113:cleanup_file_variables Cleaning up project directory and file based variables section_end:1738591114:cleanup_file_variables Job succeeded