jfrog / jfrog/frogbot

Secret Scanner publishes scan being ran as a secret finding to xray

Open
#1,295 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Go
Stars
372
Forks
107
Avg merge
2d 20h
Merged PRs (30d)
5

Description

Describe the bug

I am running Frogbot CLI against bitbucket server repos. There is a bug where frogbot is pushing scans being ran as a secret finding to xray. The Description of the finding is The scanner REQ.SECRET.GENERIC.TEXT has ran with an empty file path.

Running the latest version (2.32.2) of frogbot at the time of this issue creation on a self-hosted artifactory instance.

Current behavior

There are no errors in the logs. The scan completes successfully.
Image

Reproduction steps

No response

Expected behavior

No response

JFrog Frogbot version

2.32.2

Package manager info

Occurs on a bunch of package types, Gradle, Ant, Maven, Html/css/js

Git provider

Bitbucket Server

JFrog Frogbot configuration yaml file
- params:
    git:
      repoName: my-repo-name
      branches:
        - master

Operating system type and version

ubuntu 24.04

JFrog Xray version

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file, test, reproduction steps, or expected behavior is named. Start by reproducing the Frogbot CLI scan with the provided configuration against a Bitbucket Server repository, then trace the Xray publishing flow and inspect the generated finding. Done means the scan-run message is no longer published as a secret finding with an empty file path.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.