Checkmarx / ast-jetbrains-plugin

The CxAST JetBrains plugin enables you to import results from a CxAST scan directly into your IDE.
https://plugins.jetbrains.com/plugin/17672-checkmarx-ast
Apache License 2.0
2 stars 3 forks source link

JetBrains | Upgrade Java Wrapper version (AST-41951) #253

Closed AlvoBen closed 5 months ago

AlvoBen commented 5 months ago

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Upgrade Java Wrapper version

References

https://checkmarx.atlassian.net/browse/AST-41951

Testing

Describe how this change was tested. Be specific about anything not tested and reasons why. If this solution has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Checklist

github-actions[bot] commented 5 months ago

Logo Checkmarx One – Scan Summary & Details69d770f2-e62b-443c-8d18-33b8b7d056be

Policy Management Violations

Policy Name Rule(s) Break Build
[SAST-ML0] Not allowed NEW Sast vulnerabilities true

New Issues

Severity Issue Source File / Package Checkmarx Insight
MEDIUM Unpinned Actions Full Length Commit SHA /test-ui-windows.yml: 33 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: 23 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: 14 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /test-ui-ubuntu.yml: 33 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /pr-label.yml: 15 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /delete-dev-releases.yml: 28 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 136 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /ci.yml: 38 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /test-ui-mac.yml: 34 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /checkmarx-one-scan.yml: 19 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...

Fixed Issues

Severity Issue Source File / Package
HIGH CVE-2019-17571 Gradle-log4j:log4j-1.2.17
HIGH CVE-2021-4104 Gradle-log4j:log4j-1.2.17
HIGH CVE-2022-23302 Gradle-log4j:log4j-1.2.17
HIGH CVE-2022-23305 Gradle-log4j:log4j-1.2.17
HIGH CVE-2022-23307 Gradle-log4j:log4j-1.2.17
MEDIUM CVE-2020-15250 Gradle-junit:junit-4.10
MEDIUM CVE-2020-15250 Gradle-junit:junit-4.12
LOW Log_Forging /src/main/java/com/checkmarx/intellij/tool/window/CxToolWindowPanel.java: 438
LOW Log_Forging /src/main/java/com/checkmarx/intellij/tool/window/CxToolWindowPanel.java: 438
LOW Log_Forging /src/main/java/com/checkmarx/intellij/tool/window/CxToolWindowPanel.java: 438
LOW Log_Forging /src/main/java/com/checkmarx/intellij/tool/window/CxToolWindowPanel.java: 438
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /src/main/java/com/checkmarx/intellij/Utils.java: 42
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /src/main/java/com/checkmarx/intellij/Utils.java: 42
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /src/main/java/com/checkmarx/intellij/Utils.java: 42
LOW Use_of_Broken_or_Risky_Cryptographic_Algorithm /src/main/java/com/checkmarx/intellij/Utils.java: 42