Checkmarx / ast-cli

A CLI project wrapping application security testing (AST) APIs
Apache License 2.0
41 stars 25 forks source link

Print policy violations only if any rule was violated (AST-66024) #879

Closed sarahCx closed 2 months ago

sarahCx commented 2 months ago

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Check if there was no role that was violated in the policy, the policy will not be displayed in the PR decoration and in console summary.

References

https://checkmarx.atlassian.net/browse/AST-66024

Testing

To console summery: the test verifies that when there are no policy violations, the message "policy management violation" will not be printed. To PR Decoration: the test verifies that when there are no policy violations, the policy will not be send to github.

Checklist

github-actions[bot] commented 2 months ago

Logo Checkmarx One – Scan Summary & Detailsb6e18010-9c5d-4e9a-9d87-a35be54bce4a

Policy Management Violations

Policy Name Rule(s) Break Build
[SAST-ML0] Not allowed NEW Sast vulnerabilities true

Fixed Issues

Severity Issue Source File / Package
MEDIUM CVE-2023-49559 Go-github.com/vektah/gqlparser/v2-v2.4.5