Veracode Security Scan #390
nigthlySecurityScan.yml
on: schedule
Veracode SCA scan
51s
Veracode SAST policy scan
8m 22s
Annotations
1 error and 4 warnings
Veracode SCA scan
Veraocde SCA Scan failed with exit code 7
Veracode SCA agent scanning engine ready
Running the NPM scanner
npm warn config only Use `--omit=dev` to omit dev dependencies from the install.
Scanning completed
Found 0 lines of code
Processing results...
Processing results complete
Summary Report
Scan ID 46eb1478-c76b-4720-a5ba-7ede57734f5a
Scan Date & Time Aug 13 2024 04:05AM UTC
Account type ENTERPRISE
Scan engine 3.8.71 (latest 3.8.71)
Analysis time 39 seconds
User runner
Project /home/runner/work/veracode-sca/veracode-sca
Package Manager(s) NPM
Open-Source Libraries
Total Libraries 161
Direct Libraries 3
Transitive Libraries 160
Vulnerable Libraries 3
Third Party Code 100%
Security
With Vulnerable Methods 0
Critical Risk Vulnerabilities 0
High Risk Vulnerabilities 1
Medium Risk Vulnerabilities 2
Low Risk Vulnerabilities 0
Vulnerabilities - Public Data
CVE-2024-41818 High Risk Regular Expression Denial Of Service (ReDoS) fast-xml-parser 4.4.0
CVE-2024-39249 Medium Risk Regular Expression Denial Of Service (ReDoS) async 3.2.5
Vulnerabilities - Premium Data
NO-CVE Medium Risk Memory Leak inflight 1.0.6
Licenses
Unique Library Licenses 8
Libraries Using GPL 0
Libraries With High Risk License 0
Libraries With Medium Risk License 0
Libraries With Low Risk License 161
Libraries With Multiple Licenses 2
Libraries With Unassessable License 2
Libraries With Unrecognizable License 0
Issues
Issue ID Issue Type Severity Description Library Name & Version In Use
201254253 Vulnerability 6.2 NO-CVE: Memory Leak inflight 1.0.6
302273625 Outdated Library 3.0 Latest version at scan: 6.0.0 @actions/github 5.1.1
309152806 Vulnerability 5.3 CVE-2024-39249: Regular Expression Denial Of Service (ReDoS) async 3.2.5
316181792 Vulnerability 7.5 CVE-2024-41818: Regular Expression Denial Of Service (ReDoS) fast-xml-parser 4.4.0
317236620 Outdated Library 3.0 Latest version at scan: 2.1.9 @actions/artifact 2.1.7
Full Report Details https://sca.analysiscenter.veracode.com/teams/700tzKDV/scans/71800611
|
Veracode SCA scan
The following actions uses node12 which is deprecated and will be forced to run on node16: actions/checkout@v2. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
|
Veracode SCA scan
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v2, veracode/[email protected]. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
Veracode SAST policy scan
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
Deprecation notice: v1, v2, and v3 of the artifact actions
The following artifacts were uploaded using a version of actions/upload-artifact that is scheduled for deprecation: "Veracode Agent Based SCA Results".
Please update your workflow to use v4 of the artifact actions.
Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
|
Artifacts
Produced during runtime
Name | Size | |
---|---|---|
Veracode Agent Based SCA Results
|
3.01 KB |
|