semgrep-appsec-custom-rules
Passed Started
by
@stomlinson

Simon Tomlinson
222:14:35 on blue-2.shared-gitlab-org.runners-manager.gitlab.com/default NL4gfoBe, system ID: s_74c3e1316164822:14:49Using docker image sha256:8afaf0ecf7b18f8e39c1260c5699268bf10b7ab8231b1a2b30a1e7969f5f87a2 for returntocorp/semgrep with digest returntocorp/semgrep@sha256:f35c7891e2030110a84a721fdd556ce8f3da6e7e69d7fab1d3660ae1bb334474 ...1022:14:54Running on runner-nl4gfobe-project-278964-concurrent-0 via runner-nl4gfobe-shared-gitlab-org-1731441127-d34928f3...2722:15:32Using docker image sha256:8afaf0ecf7b18f8e39c1260c5699268bf10b7ab8231b1a2b30a1e7969f5f87a2 for returntocorp/semgrep with digest returntocorp/semgrep@sha256:f35c7891e2030110a84a721fdd556ce8f3da6e7e69d7fab1d3660ae1bb334474 ...3422:15:34$ rm "${CI_BUILDS_DIR}/sast-custom-rules/.gitlab-ci.yml" # semgrep fails when there are yaml files that are not rules # collapsed multi-line command4522:15:40No .semgrepignore found. Using default .semgrepignore rules. See the docs for the list of default ignores: https://semgrep.dev/docs/cli-usage/#ignore-files4822:15:40- builds.sast-custom-rules.appsec-pings.glappsec_eslint-disable-next-line-no-unsanitized-property_disable_gitlabsecurity6622:15:40- builds.sast-custom-rules.secure-coding-guidelines.ruby.glappsec_bad-deserialization-yaml7022:15:40- builds.sast-custom-rules.secure-coding-guidelines.ruby.glappsec_insecure-archive-operation7322:15:40- builds.sast-custom-rules.secure-coding-guidelines.ruby.glappsec_insecure-url-construction7922:15:40- builds.sast-custom-rules.secure-coding-guidelines.ruby.glappsec_unsafe-http-library-usage9522:15:40 Will report findings introduced by these commits (may be incomplete for shallow checkouts):10022:15:51No .semgrepignore found. Using default .semgrepignore rules. See the docs for the list of default ignores: https://semgrep.dev/docs/cli-usage/#ignore-files13722:15:57 Scan skipped: 1 files not matching --include patterns, 1 files matching --exclude patterns14222:15:57Yojson__Common.Json_error("Line 1, bytes 160-194:\nExpected ',' or '}' but found 'Balu\" C\", \"commit_author_email\": '")14422:15:57Called from Yojson__Safe.read_object_sep in file "lib/read.ml" (inlined), line 2343, characters 3-4714522:15:57Called from Semgrep_output_v1_j.read_contributor in file "OSS/src/rule/semgrep_output_v1_j.ml", line 23786, characters 8-4014622:15:57Called from Semgrep_output_v1_j.read_contribution in file "OSS/src/rule/semgrep_output_v1_j.ml", line 24044, characters 21-12214722:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 107, characters 16-1914822:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7114922:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115022:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115122:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115222:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115322:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115422:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115522:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115622:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115722:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115822:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7115922:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116022:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116122:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116222:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116322:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116422:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116522:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116622:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116722:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116822:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7116922:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117022:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117122:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117222:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117322:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117422:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117522:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117622:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117722:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117822:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7117922:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7118022:15:57Called from List_.fast_map in file "OSS/libs/commons/List_.ml", line 110, characters 33-7118222:15:57Called from RPC.handle_single_request in file "OSS/src/rpc/RPC.ml", line 131, characters 8-2918522:15:57Not sending pseudonymous metrics since metrics are configured to OFF and registry usage is False18922:15:58WARNING: Upload request redirected location=https://gitlab.com/api/v4/jobs/8340695738/artifacts?artifact_format=zip&artifact_type=archive&expire_in=30+days new-url=https://gitlab.com19122:16:00Uploading artifacts as "archive" to coordinator... 201 Created id=8340695738 responseStatus=201 Created token=glcbt-66