Checkmarx / ast-azure-plugin

The CxAST Azure DevOps plugin enables you to trigger SAST, SCA, and KICS scans directly from an Azure DevOps pipeline.
https://marketplace.visualstudio.com/items?itemName=checkmarx.checkmarx-ast-azure-plugin
Apache License 2.0
4 stars 2 forks source link

Update wrapper to version 0.0.93 with CLI 2.1.14 (AST-43852) #516

Closed OrShamirCM closed 4 months ago

OrShamirCM commented 4 months ago

Description

Update wrapper with bug fixes

References

AST-43852 - SCA Snoozed and muted dependencies ignored in last version of Cx CLI

Testing

unit/integration

Checklist

github-actions[bot] commented 4 months ago

Logo Checkmarx One – Scan Summary & Details9ce51de7-558f-4b63-8f6b-141537f70751

Policy Management Violations

Policy Name Rule(s) Break Build
[SAST-ML0] Not allowed NEW Sast vulnerabilities true

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2024-4068 Npm-braces-3.0.2 Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.5 Vulnerable Package
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: [14](https://github.com/Checkmarx/ast-azure-plugin/blob/feature/update-wrapper//.github/workflows/dependabot-auto-merge.yml# L14) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /pr-label.yml: [10](https://github.com/Checkmarx/ast-azure-plugin/blob/feature/update-wrapper//.github/workflows/pr-label.yml# L10) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: [101](https://github.com/Checkmarx/ast-azure-plugin/blob/feature/update-wrapper//.github/workflows/release.yml# L101) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: [68](https://github.com/Checkmarx/ast-azure-plugin/blob/feature/update-wrapper//.github/workflows/release.yml# L68) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: [88](https://github.com/Checkmarx/ast-azure-plugin/blob/feature/update-wrapper//.github/workflows/release.yml# L88) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /ast-scan.yml: [12](https://github.com/Checkmarx/ast-azure-plugin/blob/feature/update-wrapper//.github/workflows/ast-scan.yml# L12) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: [23](https://github.com/Checkmarx/ast-azure-plugin/blob/feature/update-wrapper//.github/workflows/dependabot-auto-merge.yml# L23) Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...

Fixed Issues

Severity Issue Source File / Package
HIGH CVE-2022-37614 Npm-mockery-2.1.0
HIGH Cxab55612e-3a56 Npm-braces-3.0.2
HIGH Cxca84a1c2-1f12 Npm-micromatch-4.0.5