Skip to content

Semgrep integrations-tests fail #1399

@RamiSouai

Description

@RamiSouai

🐞 Bug report

The Semgrep scanner integrations-test scan does not find any vulnerabilities in the example file.

Additional context

Currently, we use the semgrep ruleset "ci" on a python file containing exactly three vulnerabilities with the id "command-injection-os-system". This rule is however no longer present in the "ci" ruleset, which leads to our scans finding no vulnerabilities, and thus failed assertion in the test.

Metadata

Metadata

Assignees

Labels

bugBugsciChanges to the continuous integration setup

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions