whitesource / unified-agent-distribution

51 stars 48 forks source link

[Bug] Too many false-positive #45

Open Drjacky opened 1 year ago

Drjacky commented 1 year ago

I tried it on my Android repo but, almost all of the issued cases were false-positive. For example https://github.com/Drjacky/MVIModularizationTemplate/issues/19

It says there is an issue with kotlin-stdlib-1.4.31.jar but, neither my repo nor the internal library(root dependency) use that version:

Screen Shot 2022-10-25 at 17 34 31

Third-library: https://github.com/detekt/sarif4k/blob/main/build.gradle.kts

Drjacky commented 1 year ago

As you see, they have updated from 1.4.31 on 29th April, 2022: https://github.com/detekt/sarif4k/commit/bb1c8204aed9b176cd4f7143db8ec08fdde5e0fa

LenaKleyner commented 1 year ago

Hi @Drjacky,

Could you please open a ticket in our support portal with all the relevant information (the Unified Agent execution command, its settings, and the output log)?

Thanks!

Lena

Drjacky commented 1 year ago

But isn't it only for Mend Core paying customers? I tried but:

Screenshot 2022-10-26 at 18 13 33
LenaKleyner commented 1 year ago

In this case, could you please send an Email to support@mend.io?

Drjacky commented 1 year ago

Done.