-
Notifications
You must be signed in to change notification settings - Fork 59
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sarif output appears to be duplicated and invalid #704
Comments
I suspect the duplication might be due to using That's not particularly useful if it is just concatenating two JSON outputs together if that is the case |
Hi @flcdrg , |
I was under the impression that would result in addition information being included the the report, which sounded useful? |
Running jf bs with |
Hi @flcdrg |
Still an issue, at least w.r.t. invalid output. This is using CLI version 2.40.0
|
While not completely valid SARIF, as of version 2.52.1 of the jfrog cli, the SARIF produced by |
Describe the bug
Output from
jf build number --vuln=true --fail=true --server-id "server" --format sarif
does not validate when uploaded to https://sarifweb.azurewebsites.net/ValidationThe actual output is duplicated and contains invalid elements.
Current behavior
This is the output from the above command.
No, I didn't paste twice - the output seems to be duplicated (such that it is not even valid JSON!
Removing the duplication, it also contains errors according to the online validator.
Reproduction steps
Ran command in description against a .NET project with a vulnerable NuGet package.
Expected behavior
Valid sarif outputted
JFrog CLI-Core version
2.34.6
JFrog CLI version (if applicable)
2.34.6
Operating system type and version
Windows 2019
JFrog Artifactory version
Current hosted version
JFrog Xray version
Current hosted version
The text was updated successfully, but these errors were encountered: