Title: "Failed to attach findings to engagement" error when sending trivy k8s scan results to DefectDojo · Issue #2271 · secureCodeBox/secureCodeBox · GitHub
Open Graph Title: "Failed to attach findings to engagement" error when sending trivy k8s scan results to DefectDojo · Issue #2271 · secureCodeBox/secureCodeBox
X Title: "Failed to attach findings to engagement" error when sending trivy k8s scan results to DefectDojo · Issue #2271 · secureCodeBox/secureCodeBox
Description: 🐞 Bug report Describe the bug We scan Kubernetes cluster using trivy k8s command with the flag --scanners=misconfig,rbac and the hook secureCodeBox/persistence-defectdojo fails with the following error: Exception in thread "main" io.secu...
Open Graph Description: 🐞 Bug report Describe the bug We scan Kubernetes cluster using trivy k8s command with the flag --scanners=misconfig,rbac and the hook secureCodeBox/persistence-defectdojo fails with the following e...
X Description: 🐞 Bug report Describe the bug We scan Kubernetes cluster using trivy k8s command with the flag --scanners=misconfig,rbac and the hook secureCodeBox/persistence-defectdojo fails with the following e...
Opengraph URL: https://github.com/secureCodeBox/secureCodeBox/issues/2271
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"\"Failed to attach findings to engagement\" error when sending trivy k8s scan results to DefectDojo","articleBody":"## 🐞 Bug report\r\n\u003c!--\r\nThank you for reporting an issue in our project 🙌\r\n\r\nBefore opening a new issue, please make sure that we do not have any duplicates already open. You can ensure this by searching the issue list for this repository. If there is a duplicate, please close your issue and add a comment to the existing issue instead.\r\n--\u003e\r\n\r\n### Describe the bug\r\n\r\nWe scan Kubernetes cluster using `trivy k8s` command with the flag `--scanners=misconfig,rbac` and the hook `secureCodeBox/persistence-defectdojo` fails with the following error:\r\n\r\n```\r\nException in thread \"main\" io.securecodebox.persistence.defectdojo.exception.PersistenceException: Failed to attach findings to engagement.\r\n\tat io.securecodebox.persistence.defectdojo.service.DefaultImportScanService.createFindings(DefaultImportScanService.java:124)\r\n\tat io.securecodebox.persistence.defectdojo.service.DefaultImportScanService.reimportScan(DefaultImportScanService.java:75)\r\n\tat io.securecodebox.persistence.strategies.VersionedEngagementsStrategy.run(VersionedEngagementsStrategy.java:105)\r\n\tat io.securecodebox.persistence.DefectDojoPersistenceProvider.main(DefectDojoPersistenceProvider.java:43)\r\n```\r\n### Steps To Reproduce\r\n\r\nRun trivy scan with the following yaml:\r\n```\r\napiVersion: \"execution.securecodebox.io/v1\"\r\nkind: Scan\r\nmetadata:\r\n name: \"trivy-k8s\"\r\nspec:\r\n scanType: \"trivy-k8s\"\r\n parameters:\r\n - \"--scanners\"\r\n - \"misconfig,rbac\"\r\n - \"cluster\"\r\n```\r\n\r\nCheck if the hook `persistence-defectdojo` succeeds.\r\n\r\n### Expected behavior\r\n\r\nThe hook should succeed.\r\n\r\n### System (please complete the following information):\r\n\r\n- operator-4.3.0\r\n- trivy-4.3.0\r\n- persistence-defectdojo-4.3.0\r\n\r\nGoogle Kubernetes Engine\r\n\r\n```\r\nClient Version: version.Info{Major:\"1\", Minor:\"25\", GitVersion:\"v1.25.4\", GitCommit:\"872a965c6c6526caa949f0c6ac028ef7aff3fb78\", GitTreeState:\"clean\", BuildDate:\"2022-11-09T13:28:30Z\", GoVersion:\"go1.19.3\", Compiler:\"gc\", Platform:\"darwin/arm64\"}\r\nKustomize Version: v4.5.7\r\nServer Version: version.Info{Major:\"1\", Minor:\"26\", GitVersion:\"v1.26.10-gke.1101000\", GitCommit:\"375ed214cfa092ed25d2472c1709db5d7dcda078\", GitTreeState:\"clean\", BuildDate:\"2023-11-06T09:23:17Z\", GoVersion:\"go1.20.10 X:boringcrypto\", Compiler:\"gc\", Platform:\"linux/amd64\"}\r\n```\r\n\r\n### Screenshots / Logs\r\n\u003c!-- If applicable, add screenshots to help explain your problem. --\u003e\r\n\r\n### Additional context\r\n\u003c!-- Add any other context about the problem here. --\u003e\r\n","author":{"url":"https://github.com/danil-smirnov","@type":"Person","name":"danil-smirnov"},"datePublished":"2024-02-09T09:45:59.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":4},"url":"https://github.com/2271/secureCodeBox/issues/2271"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:b60a37c3-e277-c715-5064-fa01d580b00f |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | C558:30E8A:6295BB3:81CABC5:69750320 |
| html-safe-nonce | dcc92d05df550b5c05d4928d87d514c8793bc912b101f0c1d82fa5c56cbb4420 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDNTU4OjMwRThBOjYyOTVCQjM6ODFDQUJDNTo2OTc1MDMyMCIsInZpc2l0b3JfaWQiOiI2OTE5NzY4MjU3ODU0NzY3OTA0IiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | b367b9a3fe8fb26029e34f220da006258abb0a3a7626ad38d77a8d4bb6ed917b |
| hovercard-subject-tag | issue:2126791843 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/secureCodeBox/secureCodeBox/2271/issue_layout |
| twitter:image | https://opengraph.githubassets.com/7dcd533db65fccc05a5a4766877372b2279df613a9d21b05968801ec1fbeb86b/secureCodeBox/secureCodeBox/issues/2271 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/7dcd533db65fccc05a5a4766877372b2279df613a9d21b05968801ec1fbeb86b/secureCodeBox/secureCodeBox/issues/2271 |
| og:image:alt | 🐞 Bug report Describe the bug We scan Kubernetes cluster using trivy k8s command with the flag --scanners=misconfig,rbac and the hook secureCodeBox/persistence-defectdojo fails with the following e... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | danil-smirnov |
| hostname | github.com |
| expected-hostname | github.com |
| None | 4a4bf5f4e28041a9d2e5c107d7d20b78b4294ba261cab243b28167c16a623a1f |
| turbo-cache-control | no-preview |
| go-import | github.com/secureCodeBox/secureCodeBox git https://github.com/secureCodeBox/secureCodeBox.git |
| octolytics-dimension-user_id | 34573705 |
| octolytics-dimension-user_login | secureCodeBox |
| octolytics-dimension-repository_id | 80711933 |
| octolytics-dimension-repository_nwo | secureCodeBox/secureCodeBox |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 80711933 |
| octolytics-dimension-repository_network_root_nwo | secureCodeBox/secureCodeBox |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 488b30e96dfd057fbbe44c6665ccbc030b729dde |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width