jfrog / jfrog/jfrog-cli-security
JAS scan results should be displayed even if SCA failed
Open
Nobody has claimed this yet.
bug
- Dominant language
- Go
- Stars
- 13
- Forks
- 50
- Avg merge
- 3d 48m
- Merged PRs (30d)
- 26
Description
Describe the bug
No JAS audit results when there are issues in SCA scan.
Current behavior
When I run jf audit on a project that won't compile, the iac, secrets, and sast scanners all fire up, but there are no results displayed:
Reproduction steps
Run jf audit on a project that does not compile.
Expected behavior
This the expected results:
JFrog CLI version
2.51.1
Operating system type and version
MacOS
JFrog Artifactory version
No response
JFrog Xray version
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the issue with jf audit on a project that does not compile, then trace how scan results are handled when SCA fails. Done means JAS audit results are displayed alongside the other scanner results despite the SCA failure.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- cli, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100