Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SOAR-18529] Insight IVM Cloud (fedRAMP), SDK Bump and vuln #3022

Merged
merged 1 commit into from
Dec 19, 2024

ivmc sdk and vuln

d769edb
Select commit
Loading
Failed to load commit list.
Merged

[SOAR-18529] Insight IVM Cloud (fedRAMP), SDK Bump and vuln #3022

ivmc sdk and vuln
d769edb
Select commit
Loading
Failed to load commit list.
Jenkins EKS - SOAR / Jenkins succeeded Dec 19, 2024 in 4m 21s

Success

SonarQube Analysis / Shell Script

Error in sh step, with arguments /home/jenkins/agent/tools/hudson.plugins.sonar.SonarRunnerInstallation/SonarQube/bin/sonar-scanner -Dsonar.host.url=https://sonarqube.build.r7ops.com/ -Dsonar.projectKey=insightconnect-plugins -Dsonar.projectName=insightconnect-plugins.

script returned exit code 1
Build log
[2024-12-19T16:36:38.992Z] + /home/jenkins/agent/tools/hudson.plugins.sonar.SonarRunnerInstallation/SonarQube/bin/sonar-scanner -Dsonar.host.url=https://sonarqube.build.r7ops.com/ -Dsonar.projectKey=insightconnect-plugins -Dsonar.projectName=insightconnect-plugins
[2024-12-19T16:36:38.992Z] Picked up JAVA_TOOL_OPTIONS: -Dfile.encoding=UTF-8
[2024-12-19T16:36:38.992Z] INFO: Scanner configuration file: /home/jenkins/agent/tools/hudson.plugins.sonar.SonarRunnerInstallation/SonarQube/conf/sonar-scanner.properties
[2024-12-19T16:36:38.992Z] INFO: Project root configuration file: NONE
[2024-12-19T16:36:39.250Z] INFO: SonarScanner 5.0.1.3006
[2024-12-19T16:36:39.250Z] INFO: Java 17.0.13 Eclipse Adoptium (64-bit)
[2024-12-19T16:36:39.250Z] INFO: Linux 6.1.119-129.201.amzn2023.x86_64 amd64
[2024-12-19T16:36:39.250Z] INFO: User cache: /home/jenkins/.sonar/cache
[2024-12-19T16:36:40.182Z] INFO: Analyzing on SonarQube server 10.8.0.100206
[2024-12-19T16:36:40.183Z] INFO: Default locale: "en_US", source code encoding: "UTF-8" (analysis is platform dependent)
[2024-12-19T16:36:41.180Z] INFO: Load global settings
[2024-12-19T16:36:41.180Z] INFO: Load global settings (done) | time=104ms
[2024-12-19T16:36:41.180Z] INFO: Server id: 3482B4BD-AYxjbeHzB0-CTE8TC-sh
[2024-12-19T16:36:41.180Z] INFO: Loading required plugins
[2024-12-19T16:36:41.180Z] INFO: Load plugins index
[2024-12-19T16:36:41.180Z] INFO: Load plugins index (done) | time=16ms
[2024-12-19T16:36:41.180Z] INFO: Load/download plugins
[2024-12-19T16:36:41.437Z] INFO: Load/download plugins (done) | time=282ms
[2024-12-19T16:36:41.437Z] INFO: Loaded core extensions: developer-scanner, sca, server-common
[2024-12-19T16:36:41.695Z] INFO: Process project properties
[2024-12-19T16:36:41.695Z] INFO: Process project properties (done) | time=0ms
[2024-12-19T16:36:41.695Z] INFO: Project key: insightconnect-plugins
[2024-12-19T16:36:41.695Z] INFO: Base dir: /home/jenkins/agent/workspace/connect-plugins_ivmcloud-fedramp
[2024-12-19T16:36:41.695Z] INFO: Working dir: /home/jenkins/agent/workspace/connect-plugins_ivmcloud-fedramp/.scannerwork
[2024-12-19T16:36:41.695Z] INFO: Load project settings for component key: 'insightconnect-plugins'
[2024-12-19T16:36:41.952Z] INFO: Load project branches
[2024-12-19T16:36:41.952Z] INFO: Load project branches (done) | time=5ms
[2024-12-19T16:36:41.952Z] INFO: Load branch configuration
[2024-12-19T16:36:41.952Z] INFO: Detected branch/PR in 'Jenkins'
[2024-12-19T16:36:41.952Z] INFO: Auto-configuring branch 'ivmcloud-fedramp'
[2024-12-19T16:36:41.952Z] INFO: Load branch configuration (done) | time=1ms
[2024-12-19T16:36:41.952Z] INFO: Load quality profiles
[2024-12-19T16:36:41.952Z] INFO: Load quality profiles (done) | time=48ms
[2024-12-19T16:36:41.952Z] INFO: Auto-configuring with CI 'Jenkins'
[2024-12-19T16:36:41.952Z] INFO: Load active rules
[2024-12-19T16:36:44.481Z] INFO: Load active rules (done) | time=2427ms
[2024-12-19T16:36:44.481Z] INFO: Load analysis cache
[2024-12-19T16:36:44.481Z] INFO: Load analysis cache (404) | time=5ms
[2024-12-19T16:36:44.481Z] INFO: Branch name: ivmcloud-fedramp
[2024-12-19T16:36:44.481Z] INFO: Preprocessing files...
[2024-12-19T16:36:47.759Z] INFO: 4 languages detected in 14854 preprocessed files
[2024-12-19T16:36:47.759Z] INFO: 1 file ignored because of scm ignore settings
[2024-12-19T16:36:47.759Z] INFO: Loading plugins for detected languages
[2024-12-19T16:36:47.759Z] INFO: Load/download plugins
[2024-12-19T16:36:49.130Z] INFO: Load/download plugins (done) | time=1105ms
[2024-12-19T16:36:49.130Z] INFO: Sonar Cryptography initialized in context (SONARQUBE)
[2024-12-19T16:36:49.130Z] INFO: Load project repositories
[2024-12-19T16:36:49.130Z] INFO: Load project repositories (done) | time=10ms
[2024-12-19T16:36:49.130Z] INFO: Indexing files...
[2024-12-19T16:36:49.130Z] INFO: Project configuration:
[2024-12-19T16:36:50.082Z] INFO: 14854 files indexed
[2024-12-19T16:36:50.082Z] INFO: Quality profile for docker: Sonar way
[2024-12-19T16:36:50.082Z] INFO: Quality profile for json: Sonar way
[2024-12-19T16:36:50.082Z] INFO: Quality profile for py: Sonar way
[2024-12-19T16:36:50.082Z] INFO: Quality profile for yaml: Sonar way
[2024-12-19T16:36:50.082Z] INFO: ------------- Run sensors on module insightconnect-plugins
[2024-12-19T16:36:50.082Z] INFO: Sonar Cryptography initialized in context (SONARQUBE)
[2024-12-19T16:36:50.082Z] INFO: Load metrics repository
[2024-12-19T16:36:50.082Z] INFO: Load metrics repository (done) | time=15ms
[2024-12-19T16:36:51.014Z] INFO: Sensor Python Sensor [python]
[2024-12-19T16:36:51.014Z] WARN: Your code is analyzed as compatible with all Python 3 versions by default. You can get a more precise analysis by setting the exact Python version in your configuration via the parameter "sonar.python.version"
[2024-12-19T16:36:51.272Z] INFO: Starting global symbols computation
[2024-12-19T16:36:51.272Z] INFO: 9535 source files to be analyzed
[2024-12-19T16:37:01.272Z] INFO: 3126/9535 files analyzed, current file: plugins/rapid7_insightvm_cloud/icon_rapid7_insightvm_cloud/connection/connection.py
[2024-12-19T16:37:13.482Z] INFO: 7578/9535 files analyzed, current file: plugins/file_info/icon_file_info/actions/get_file_info/action.py
[2024-12-19T16:37:15.378Z] WARN: Invalid character encountered in file /home/jenkins/agent/workspace/connect-plugins_ivmcloud-fedramp/plugins/url_encoder/unit_test/test_decode.py at line 86 for encoding UTF-8. Please fix file content or configure the encoding to be used using property 'sonar.sourceEncoding'.
[2024-12-19T16:37:15.635Z] INFO: 9535/9535 source files have been analyzed
[2024-12-19T16:37:16.199Z] INFO: Starting rules execution
[2024-12-19T16:37:16.199Z] INFO: 9535 source files to be analyzed
[2024-12-19T16:37:26.186Z] INFO: 479/9535 files analyzed, current file: plugins/carbon_black_response/icon_carbon_black_response/actions/list_sensors/__init__.py
[2024-12-19T16:37:36.144Z] INFO: 1281/9535 files analyzed, current file: plugins/active_directory_ldap/komand_active_directory_ldap/actions/enable_user/schema.py
[2024-12-19T16:37:46.097Z] INFO: 2155/9535 files analyzed, current file: plugins/mcafee_epo/komand_mcafee_epo/actions/tag_system/action.py
[2024-12-19T16:37:58.291Z] INFO: 3052/9535 files analyzed, current file: plugins/graphite/icon_graphite/actions/metrics_expand/schema.py
[2024-12-19T16:38:06.386Z] INFO: 3954/9535 files analyzed, current file: plugins/cisco_firepower_management_center/unit_test/util.py
[2024-12-19T16:38:16.345Z] INFO: 4794/9535 files analyzed, current file: plugins/palo_alto_mine_meld/icon_palo_alto_mine_meld/util/__init__.py
[2024-12-19T16:38:26.322Z] INFO: 5698/9535 files analyzed, current file: plugins/p0f/komand_p0f/connection/schema.py
[2024-12-19T16:38:36.283Z] INFO: 6584/9535 files analyzed, current file: plugins/rapid7_insightvm/komand_rapid7_insightvm/actions/tag_assets/schema.py
[2024-12-19T16:38:46.241Z] INFO: 7469/9535 files analyzed, current file: plugins/rapid7_insightidr/komand_rapid7_insightidr/actions/replace_indicators/__init__.py
[2024-12-19T16:38:56.217Z] INFO: 8323/9535 files analyzed, current file: plugins/crowdstrike_falcon_intelligence/icon_crowdstrike_falcon_intelligence/util/api.py
[2024-12-19T16:39:06.174Z] INFO: 9116/9535 files analyzed, current file: plugins/azure_sentinel/icon_azure_sentinel/actions/query_indicator/action.py
[2024-12-19T16:39:11.448Z] INFO: 9535/9535 source files have been analyzed
[2024-12-19T16:39:11.448Z] INFO: The Python analyzer was able to leverage cached data from previous analyses for 0 out of 9535 files. These files were not parsed.
[2024-12-19T16:39:11.448Z] INFO: Sensor Python Sensor [python] (done) | time=140510ms
[2024-12-19T16:39:11.448Z] INFO: Sensor Cobertura Sensor for Python coverage [python]
[2024-12-19T16:39:12.380Z] INFO: Sensor Cobertura Sensor for Python coverage [python] (done) | time=1112ms
[2024-12-19T16:39:12.380Z] INFO: Sensor PythonXUnitSensor [python]
[2024-12-19T16:39:13.753Z] INFO: Sensor PythonXUnitSensor [python] (done) | time=1103ms
[2024-12-19T16:39:13.753Z] INFO: Sensor JaCoCo XML Report Importer [jacoco]
[2024-12-19T16:39:13.753Z] INFO: 'sonar.coverage.jacoco.xmlReportPaths' is not defined. Using default locations: target/site/jacoco/jacoco.xml,target/site/jacoco-it/jacoco.xml,build/reports/jacoco/test/jacocoTestReport.xml
[2024-12-19T16:39:13.753Z] INFO: No report imported, no coverage information will be imported by JaCoCo XML Report Importer
[2024-12-19T16:39:13.753Z] INFO: Sensor JaCoCo XML Report Importer [jacoco] (done) | time=1ms
[2024-12-19T16:39:13.753Z] INFO: Sensor IaC Ansible Sensor [iacenterprise]
[2024-12-19T16:39:14.010Z] INFO: 0 source files to be analyzed
[2024-12-19T16:39:14.010Z] INFO: 0/0 source files have been analyzed
[2024-12-19T16:39:14.010Z] INFO: Sensor IaC Ansible Sensor [iacenterprise] (done) | time=384ms
[2024-12-19T16:39:14.010Z] INFO: Sensor IaC CloudFormation Sensor [iac]
[2024-12-19T16:39:14.010Z] INFO: 0 source files to be analyzed
[2024-12-19T16:39:14.010Z] INFO: 0/0 source files have been analyzed
[2024-12-19T16:39:14.010Z] INFO: Sensor IaC CloudFormation Sensor [iac] (done) | time=59ms
[2024-12-19T16:39:14.010Z] INFO: Sensor IaC Kubernetes Sensor [iac]
[2024-12-19T16:39:14.267Z] INFO: 0 source files to be parsed
[2024-12-19T16:39:14.267Z] INFO: 0/0 source files have been parsed
[2024-12-19T16:39:14.267Z] INFO: 0 source files to be analyzed
[2024-12-19T16:39:14.267Z] INFO: 0/0 source files have been analyzed
[2024-12-19T16:39:14.267Z] INFO: 0 source files to be checked
[2024-12-19T16:39:14.267Z] INFO: 0/0 source files have been checked
[2024-12-19T16:39:14.267Z] INFO: Sensor IaC Kubernetes Sensor [iac] (done) | time=162ms
[2024-12-19T16:39:14.267Z] INFO: Sensor IaC AzureResourceManager Sensor [iac]
[2024-12-19T16:39:14.267Z] INFO: 0 source files to be analyzed
[2024-12-19T16:39:14.267Z] INFO: 0/0 source files have been analyzed
[2024-12-19T16:39:14.267Z] INFO: Sensor IaC AzureResourceManager Sensor [iac] (done) | time=62ms
[2024-12-19T16:39:14.267Z] INFO: Sensor Java Config Sensor [iac]
[2024-12-19T16:39:14.267Z] INFO: 0 source files to be analyzed
[2024-12-19T16:39:14.267Z] INFO: 0/0 source files have been analyzed
[2024-12-19T16:39:14.267Z] INFO: Sensor Java Config Sensor [iac] (done) | time=72ms
[2024-12-19T16:39:14.267Z] INFO: Sensor JavaScript inside YAML analysis [javascript]
[2024-12-19T16:39:14.831Z] INFO: No input files found for analysis
[2024-12-19T16:39:14.831Z] INFO: Hit the cache for 0 out of 0
[2024-12-19T16:39:14.832Z] INFO: Miss the cache for 0 out of 0
[2024-12-19T16:39:14.832Z] INFO: Sensor JavaScript inside YAML analysis [javascript] (done) | time=397ms
[2024-12-19T16:39:14.832Z] INFO: Sensor CSS Rules [javascript]
[2024-12-19T16:39:14.832Z] INFO: No CSS, PHP, HTML or VueJS files are found in the project. CSS analysis is skipped.
[2024-12-19T16:39:14.832Z] INFO: Sensor CSS Rules [javascript] (done) | time=12ms
[2024-12-19T16:39:14.832Z] INFO: Sensor Python HTML templates processing [securitypythonfrontend]
[2024-12-19T16:39:15.395Z] INFO: Sensor Python HTML templates processing [securitypythonfrontend] (done) | time=615ms
[2024-12-19T16:39:15.395Z] INFO: Sensor IaC Docker Sensor [iac]
[2024-12-19T16:39:15.395Z] INFO: 263 source files to be analyzed
[2024-12-19T16:39:16.764Z] INFO: 263/263 source files have been analyzed
[2024-12-19T16:39:16.764Z] INFO: Sensor IaC Docker Sensor [iac] (done) | time=1125ms
[2024-12-19T16:39:16.764Z] INFO: Sensor Serverless configuration file sensor [security]
[2024-12-19T16:39:16.764Z] INFO: 0 Serverless function entries were found in the project
[2024-12-19T16:39:16.764Z] INFO: 0 Serverless function handlers were kept as entrypoints
[2024-12-19T16:39:16.764Z] INFO: Sensor Serverless configuration file sensor [security] (done) | time=14ms
[2024-12-19T16:39:16.764Z] INFO: Sensor AWS SAM template file sensor [security]
[2024-12-19T16:39:16.764Z] INFO: Sensor AWS SAM template file sensor [security] (done) | time=120ms
[2024-12-19T16:39:16.764Z] INFO: Sensor AWS SAM Inline template file sensor [security]
[2024-12-19T16:39:16.764Z] INFO: Sensor AWS SAM Inline template file sensor [security] (done) | time=123ms
[2024-12-19T16:39:16.764Z] INFO: Sensor javabugs [dbd]
[2024-12-19T16:39:16.764Z] INFO: Reading IR files from: /home/jenkins/agent/workspace/connect-plugins_ivmcloud-fedramp/.scannerwork/ir/java
[2024-12-19T16:39:16.764Z] INFO: No IR files have been included for analysis.
[2024-12-19T16:39:16.764Z] INFO: Sensor javabugs [dbd] (done) | time=1ms
[2024-12-19T16:39:16.764Z] INFO: Sensor pythonbugs [dbd]
[2024-12-19T16:39:17.328Z] INFO: Reading IR files from: /home/jenkins/agent/workspace/connect-plugins_ivmcloud-fedramp/.scannerwork/ir/python
[2024-12-19T16:39:17.585Z] INFO: Analyzing 13390 functions to detect bugs.
[2024-12-19T16:39:44.121Z] INFO: ------------------------------------------------------------------------
[2024-12-19T16:39:44.121Z] INFO: EXECUTION FAILURE
[2024-12-19T16:39:44.121Z] INFO: ------------------------------------------------------------------------
[2024-12-19T16:39:44.121Z] INFO: Total time: 3:01.871s
[2024-12-19T16:39:44.121Z] INFO: Final Memory: 244M/817M
[2024-12-19T16:39:44.121Z] INFO: ------------------------------------------------------------------------
[2024-12-19T16:39:44.121Z] ERROR: Error during SonarScanner execution
[2024-12-19T16:39:44.121Z] java.lang.OutOfMemoryError: Java heap space
[2024-12-19T16:39:44.121Z] 	at java.base/java.util.LinkedList.addAll(Unknown Source)
[2024-12-19T16:39:44.121Z] 	at java.base/java.util.LinkedList.addAll(Unknown Source)
[2024-12-19T16:39:44.121Z] 	at com.sonarsource.A.J.B(na:782)
[2024-12-19T16:39:44.121Z] 	at com.sonarsource.A.F.executeChecks(na:2678)
[2024-12-19T16:39:44.121Z] 	at com.sonarsource.A.F.executeSensor(na:1978)
[2024-12-19T16:39:44.121Z] 	at com.sonarsource.A.F.execute(na:2033)
[2024-12-19T16:39:44.121Z] 	at org.sonar.scanner.sensor.AbstractSensorWrapper.analyse(AbstractSensorWrapper.java:64)
[2024-12-19T16:39:44.121Z] 	at org.sonar.scanner.sensor.ModuleSensorsExecutor.execute(ModuleSensorsExecutor.java:88)
[2024-12-19T16:39:44.121Z] 	at org.sonar.scanner.sensor.ModuleSensorsExecutor.execute(ModuleSensorsExecutor.java:64)
[2024-12-19T16:39:44.121Z] 	at org.sonar.scanner.scan.SpringModuleScanContainer.doAfterStart(SpringModuleScanContainer.java:82)
[2024-12-19T16:39:44.121Z] 	at org.sonar.core.platform.SpringComponentContainer.startComponents(SpringComponentContainer.java:226)
[2024-12-19T16:39:44.122Z] 	at org.sonar.core.platform.SpringComponentContainer.execute(SpringComponentContainer.java:205)
[2024-12-19T16:39:44.122Z] 	at org.sonar.scanner.scan.SpringProjectScanContainer.scan(SpringProjectScanContainer.java:201)
[2024-12-19T16:39:44.122Z] 	at org.sonar.scanner.scan.SpringProjectScanContainer.scanRecursively(SpringProjectScanContainer.java:197)
[2024-12-19T16:39:44.122Z] 	at org.sonar.scanner.scan.SpringProjectScanContainer.doAfterStart(SpringProjectScanContainer.java:170)
[2024-12-19T16:39:44.122Z] 	at org.sonar.core.platform.SpringComponentContainer.startComponents(SpringComponentContainer.java:226)
[2024-12-19T16:39:44.122Z] 	at org.sonar.core.platform.SpringComponentContainer.execute(SpringComponentContainer.java:205)
[2024-12-19T16:39:44.122Z] 	at org.sonar.scanner.bootstrap.SpringScannerContainer.doAfterStart(SpringScannerContainer.java:355)
[2024-12-19T16:39:44.122Z] 	at org.sonar.core.platform.SpringComponentContainer.startComponents(SpringComponentContainer.java:226)
[2024-12-19T16:39:44.122Z] 	at org.sonar.core.platform.SpringComponentContainer.execute(SpringComponentContainer.java:205)
[2024-12-19T16:39:44.122Z] 	at org.sonar.scanner.bootstrap.SpringGlobalContainer.doAfterStart(SpringGlobalContainer.java:144)
[2024-12-19T16:39:44.122Z] 	at org.sonar.core.platform.SpringComponentContainer.startComponents(SpringComponentContainer.java:226)
[2024-12-19T16:39:44.122Z] 	at org.sonar.core.platform.SpringComponentContainer.execute(SpringComponentContainer.java:205)
[2024-12-19T16:39:44.122Z] 	at org.sonar.batch.bootstrapper.Batch.doExecute(Batch.java:73)
[2024-12-19T16:39:44.122Z] 	at org.sonar.batch.bootstrapper.Batch.execute(Batch.java:67)
[2024-12-19T16:39:44.122Z] 	at org.sonarsource.scanner.api.internal.batch.BatchIsolatedLauncher.execute(BatchIsolatedLauncher.java:46)
[2024-12-19T16:39:44.122Z] 	at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
[2024-12-19T16:39:44.122Z] 	at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
[2024-12-19T16:39:44.122Z] 	at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
[2024-12-19T16:39:44.122Z] 	at java.base/java.lang.reflect.Method.invoke(Unknown Source)
[2024-12-19T16:39:44.122Z] 	at org.sonarsource.scanner.api.internal.IsolatedLauncherProxy.invoke(IsolatedLauncherProxy.java:60)
[2024-12-19T16:39:44.122Z] 	at jdk.proxy1/jdk.proxy1.$Proxy0.execute(Unknown Source)
[2024-12-19T16:39:44.122Z] ERROR: 
[2024-12-19T16:39:44.122Z] ERROR: Re-run SonarScanner using the -X switch to enable full debug logging.

Details

  • Declarative: Checkout SCM (14 sec)
    • Setup Python virtual environment and tooling (0.75 sec)
    • Retrieve git tag on SCM (0.74 sec)
    • Retrieve plugin details and announce release (0.7 sec)
    • Build plugin image using buildpacks (0.7 sec)
    • Initialize plugin release (0.77 sec)
    • SonarQube Analysis (3 min 8 sec)
      Error: script returned exit code 1
    • Push to Alliance Govcloud (0.84 sec)
    • Declarative: Post Actions (3.3 sec)