checkmarx-ltd / cx-flow

Checkmarx Scan and Result Orchestration
Apache License 2.0
88 stars 87 forks source link

Pr springboot migration final cxflow #1315

Closed satyamchaurasiapersistent closed 8 months ago

satyamchaurasiapersistent commented 8 months ago

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Describe the purpose of this PR along with any background information and the impacts of the proposed change.

References

Include supporting link to GitHub Issue/PR number

Testing

Describe how this change was tested. Be specific about anything not tested and reasons why. If this solution has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Checklist

AvivCx commented 8 months ago

Logo Checkmarx One – Scan Summary & Details65a007cf-c09e-47aa-85a1-6b87f3866658

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH WORKDIR Path Not Absolute /Dockerfile: 3 For clarity and reliability, you should always use absolute paths for your WORKDIR
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 10 Package version pinning reduces the range of versions that can be installed, reducing the chances of failure due to unanticipated changes
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 11 Package version pinning reduces the range of versions that can be installed, reducing the chances of failure due to unanticipated changes
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 12 Package version pinning reduces the range of versions that can be installed, reducing the chances of failure due to unanticipated changes
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 9 Package version pinning reduces the range of versions that can be installed, reducing the chances of failure due to unanticipated changes
MEDIUM Update Instruction Alone /Dockerfile: 4 Instruction 'RUN update' should always be followed by ' install' in the same RUN statement

Fixed Issues

Severity Issue Source File / Package
HIGH CVE-2016-1000027 Maven-org.springframework:spring-webmvc-5.3.31
HIGH CVE-2016-1000027 Maven-org.springframework:spring-web-5.3.31
HIGH CVE-2023-3635 Maven-com.squareup.okio:okio-2.8.0
HIGH WORKDIR Path Not Absolute /Dockerfile: 3
HIGH WORKDIR Path Not Absolute /Dockerfile: 21
MEDIUM CVE-2023-33201 Maven-org.bouncycastle:bcprov-jdk15on-1.70
MEDIUM CVE-2023-51074 Maven-com.jayway.jsonpath:json-path-2.7.0
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 27
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 26
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 9
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 28
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 12
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 29
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 10
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 11
MEDIUM Update Instruction Alone /Dockerfile: 22
MEDIUM Update Instruction Alone /Dockerfile: 4