Secret Scanner publishes scan being ran as a secret finding to xray
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 372
- Forks
- 107
- Avg merge
- 2d 20h
- Merged PRs (30d)
- 5
Description
Describe the bug
I am running Frogbot CLI against bitbucket server repos. There is a bug where frogbot is pushing scans being ran as a secret finding to xray. The Description of the finding is The scanner REQ.SECRET.GENERIC.TEXT has ran with an empty file path.
Running the latest version (2.32.2) of frogbot at the time of this issue creation on a self-hosted artifactory instance.
Current behavior
There are no errors in the logs. The scan completes successfully.
Reproduction steps
No response
Expected behavior
No response
JFrog Frogbot version
2.32.2
Package manager info
Occurs on a bunch of package types, Gradle, Ant, Maven, Html/css/js
Git provider
Bitbucket Server
JFrog Frogbot configuration yaml file
- params:
git:
repoName: my-repo-name
branches:
- master
Operating system type and version
ubuntu 24.04
JFrog Xray version
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file, test, reproduction steps, or expected behavior is named. Start by reproducing the Frogbot CLI scan with the provided configuration against a Bitbucket Server repository, then trace the Xray publishing flow and inspect the generated finding. Done means the scan-run message is no longer published as a secret finding with an empty file path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- cli, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100