Skip to content

Move stackId from Vulnerability to Location #8384

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Feb 17, 2025

Conversation

jandro996
Copy link
Member

@jandro996 jandro996 commented Feb 13, 2025

What Does This Do

Move stackId from Vulnerability to Location

Motivation

The RFC specifies that

Location
In order to link the stack with the vulnerability, we will add a stack field to the vulnerability’s location, containing the stack id in the vulnerabilities section of stacks of the span.

However, this stackId was incorrectly added to the vulnerability instead of to the Location.

Additional Notes

RFC

Contributor Checklist

Jira ticket: APPSEC-56772

@jandro996 jandro996 added type: bug comp: asm iast Application Security Management (IAST) labels Feb 13, 2025
@pr-commenter
Copy link

pr-commenter bot commented Feb 13, 2025

Benchmarks

Startup

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
git_branch master alejandro.gonzalez/fix-stackId-vulnerabilities
git_commit_date 1739556495 1739558441
git_commit_sha bab17ef c9a71f5
release_version 1.47.0-SNAPSHOT~bab17eff8d 1.47.0-SNAPSHOT~c9a71f54c6
See matching parameters
Baseline Candidate
application insecure-bank insecure-bank
ci_job_date 1739560980 1739560980
ci_job_id 809444946 809444946
ci_pipeline_id 55974654 55974654
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_version Linux runner-hzy35tlz-project-304-concurrent-0-me8vr9z8 6.8.0-1021-aws #23~22.04.1-Ubuntu SMP Tue Dec 10 16:50:46 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux Linux runner-hzy35tlz-project-304-concurrent-0-me8vr9z8 6.8.0-1021-aws #23~22.04.1-Ubuntu SMP Tue Dec 10 16:50:46 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux
module Agent Agent
parent None None
variant iast iast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 58 metrics, 5 unstable metrics.

Startup time reports for insecure-bank
gantt
    title insecure-bank - global startup overhead: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d

    dateFormat X
    axisFormat %s
section tracing
Agent [baseline] (1.045 s) : 0, 1045422
Total [baseline] (8.676 s) : 0, 8675944
Agent [candidate] (1.04 s) : 0, 1039787
Total [candidate] (8.676 s) : 0, 8675763
section iast
Agent [baseline] (1.169 s) : 0, 1169465
Total [baseline] (9.275 s) : 0, 9275372
Agent [candidate] (1.169 s) : 0, 1168790
Total [candidate] (9.246 s) : 0, 9245984
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.179 s) : 0, 1178849
Total [baseline] (9.297 s) : 0, 9296668
Agent [candidate] (1.175 s) : 0, 1175053
Total [candidate] (9.274 s) : 0, 9273911
section iast_TELEMETRY_OFF
Agent [baseline] (1.169 s) : 0, 1169096
Total [baseline] (9.248 s) : 0, 9247996
Agent [candidate] (1.174 s) : 0, 1174291
Total [candidate] (9.277 s) : 0, 9277092
Loading
  • baseline results
Module Variant Duration Δ tracing
Agent tracing 1.045 s -
Agent iast 1.169 s 124.043 ms (11.9%)
Agent iast_HARDCODED_SECRET_DISABLED 1.179 s 133.427 ms (12.8%)
Agent iast_TELEMETRY_OFF 1.169 s 123.673 ms (11.8%)
Total tracing 8.676 s -
Total iast 9.275 s 599.427 ms (6.9%)
Total iast_HARDCODED_SECRET_DISABLED 9.297 s 620.724 ms (7.2%)
Total iast_TELEMETRY_OFF 9.248 s 572.052 ms (6.6%)
  • candidate results
Module Variant Duration Δ tracing
Agent tracing 1.04 s -
Agent iast 1.169 s 129.004 ms (12.4%)
Agent iast_HARDCODED_SECRET_DISABLED 1.175 s 135.266 ms (13.0%)
Agent iast_TELEMETRY_OFF 1.174 s 134.504 ms (12.9%)
Total tracing 8.676 s -
Total iast 9.246 s 570.221 ms (6.6%)
Total iast_HARDCODED_SECRET_DISABLED 9.274 s 598.148 ms (6.9%)
Total iast_TELEMETRY_OFF 9.277 s 601.329 ms (6.9%)
gantt
    title insecure-bank - break down per module: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d

    dateFormat X
    axisFormat %s
section tracing
BytebuddyAgent [baseline] (720.111 ms) : 0, 720111
BytebuddyAgent [candidate] (716.865 ms) : 0, 716865
GlobalTracer [baseline] (241.241 ms) : 0, 241241
GlobalTracer [candidate] (240.055 ms) : 0, 240055
AppSec [baseline] (55.729 ms) : 0, 55729
AppSec [candidate] (55.397 ms) : 0, 55397
Remote Config [baseline] (701.415 µs) : 0, 701
Remote Config [candidate] (691.968 µs) : 0, 692
Telemetry [baseline] (12.38 ms) : 0, 12380
Telemetry [candidate] (11.56 ms) : 0, 11560
section iast
BytebuddyAgent [baseline] (834.958 ms) : 0, 834958
BytebuddyAgent [candidate] (834.733 ms) : 0, 834733
GlobalTracer [baseline] (230.01 ms) : 0, 230010
GlobalTracer [candidate] (229.617 ms) : 0, 229617
AppSec [baseline] (57.245 ms) : 0, 57245
AppSec [candidate] (57.383 ms) : 0, 57383
Remote Config [baseline] (614.007 µs) : 0, 614
Remote Config [candidate] (636.05 µs) : 0, 636
Telemetry [baseline] (8.699 ms) : 0, 8699
Telemetry [candidate] (8.669 ms) : 0, 8669
IAST [baseline] (22.761 ms) : 0, 22761
IAST [candidate] (22.571 ms) : 0, 22571
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (842.755 ms) : 0, 842755
BytebuddyAgent [candidate] (837.719 ms) : 0, 837719
GlobalTracer [baseline] (231.365 ms) : 0, 231365
GlobalTracer [candidate] (232.21 ms) : 0, 232210
AppSec [baseline] (57.093 ms) : 0, 57093
AppSec [candidate] (57.361 ms) : 0, 57361
Remote Config [baseline] (626.687 µs) : 0, 627
Remote Config [candidate] (651.053 µs) : 0, 651
Telemetry [baseline] (8.622 ms) : 0, 8622
Telemetry [candidate] (8.841 ms) : 0, 8841
IAST [baseline] (22.976 ms) : 0, 22976
IAST [candidate] (23.044 ms) : 0, 23044
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (834.217 ms) : 0, 834217
BytebuddyAgent [candidate] (838.97 ms) : 0, 838970
GlobalTracer [baseline] (230.995 ms) : 0, 230995
GlobalTracer [candidate] (230.847 ms) : 0, 230847
AppSec [baseline] (52.662 ms) : 0, 52662
AppSec [candidate] (56.633 ms) : 0, 56633
Remote Config [baseline] (612.976 µs) : 0, 613
Remote Config [candidate] (630.217 µs) : 0, 630
Telemetry [baseline] (8.66 ms) : 0, 8660
Telemetry [candidate] (8.624 ms) : 0, 8624
IAST [baseline] (26.691 ms) : 0, 26691
IAST [candidate] (23.229 ms) : 0, 23229
Loading
Startup time reports for petclinic
gantt
    title petclinic - global startup overhead: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d

    dateFormat X
    axisFormat %s
section tracing
Agent [baseline] (1.041 s) : 0, 1041441
Total [baseline] (10.473 s) : 0, 10473447
Agent [candidate] (1.044 s) : 0, 1043663
Total [candidate] (10.5 s) : 0, 10499506
section appsec
Agent [baseline] (1.194 s) : 0, 1193843
Total [baseline] (10.809 s) : 0, 10808808
Agent [candidate] (1.185 s) : 0, 1185413
Total [candidate] (10.812 s) : 0, 10812236
section iast
Agent [baseline] (1.169 s) : 0, 1169004
Total [baseline] (10.999 s) : 0, 10999404
Agent [candidate] (1.172 s) : 0, 1171797
Total [candidate] (11.0 s) : 0, 11000158
section profiling
Agent [baseline] (1.262 s) : 0, 1261854
Total [baseline] (10.894 s) : 0, 10893707
Agent [candidate] (1.261 s) : 0, 1261169
Total [candidate] (10.892 s) : 0, 10892022
Loading
  • baseline results
Module Variant Duration Δ tracing
Agent tracing 1.041 s -
Agent appsec 1.194 s 152.402 ms (14.6%)
Agent iast 1.169 s 127.563 ms (12.2%)
Agent profiling 1.262 s 220.413 ms (21.2%)
Total tracing 10.473 s -
Total appsec 10.809 s 335.361 ms (3.2%)
Total iast 10.999 s 525.956 ms (5.0%)
Total profiling 10.894 s 420.26 ms (4.0%)
  • candidate results
Module Variant Duration Δ tracing
Agent tracing 1.044 s -
Agent appsec 1.185 s 141.75 ms (13.6%)
Agent iast 1.172 s 128.133 ms (12.3%)
Agent profiling 1.261 s 217.505 ms (20.8%)
Total tracing 10.5 s -
Total appsec 10.812 s 312.73 ms (3.0%)
Total iast 11.0 s 500.651 ms (4.8%)
Total profiling 10.892 s 392.516 ms (3.7%)
gantt
    title petclinic - break down per module: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d

    dateFormat X
    axisFormat %s
section tracing
BytebuddyAgent [baseline] (717.835 ms) : 0, 717835
BytebuddyAgent [candidate] (721.585 ms) : 0, 721585
GlobalTracer [baseline] (239.9 ms) : 0, 239900
GlobalTracer [candidate] (239.972 ms) : 0, 239972
AppSec [baseline] (55.654 ms) : 0, 55654
AppSec [candidate] (55.367 ms) : 0, 55367
Remote Config [baseline] (695.976 µs) : 0, 696
Remote Config [candidate] (702.633 µs) : 0, 703
Telemetry [baseline] (12.128 ms) : 0, 12128
Telemetry [candidate] (10.768 ms) : 0, 10768
section appsec
BytebuddyAgent [baseline] (741.675 ms) : 0, 741675
BytebuddyAgent [candidate] (736.278 ms) : 0, 736278
GlobalTracer [baseline] (238.767 ms) : 0, 238767
GlobalTracer [candidate] (237.055 ms) : 0, 237055
AppSec [baseline] (178.165 ms) : 0, 178165
AppSec [candidate] (177.083 ms) : 0, 177083
Remote Config [baseline] (671.907 µs) : 0, 672
Remote Config [candidate] (669.224 µs) : 0, 669
Telemetry [baseline] (8.346 ms) : 0, 8346
Telemetry [candidate] (8.294 ms) : 0, 8294
IAST [baseline] (21.821 ms) : 0, 21821
IAST [candidate] (21.531 ms) : 0, 21531
section iast
BytebuddyAgent [baseline] (834.782 ms) : 0, 834782
BytebuddyAgent [candidate] (836.618 ms) : 0, 836618
GlobalTracer [baseline] (230.27 ms) : 0, 230270
GlobalTracer [candidate] (230.722 ms) : 0, 230722
AppSec [baseline] (56.823 ms) : 0, 56823
AppSec [candidate] (57.078 ms) : 0, 57078
Remote Config [baseline] (621.805 µs) : 0, 622
Remote Config [candidate] (626.949 µs) : 0, 627
Telemetry [baseline] (8.644 ms) : 0, 8644
Telemetry [candidate] (8.756 ms) : 0, 8756
IAST [baseline] (22.607 ms) : 0, 22607
IAST [candidate] (22.738 ms) : 0, 22738
section profiling
BytebuddyAgent [baseline] (707.629 ms) : 0, 707629
BytebuddyAgent [candidate] (707.007 ms) : 0, 707007
GlobalTracer [baseline] (351.292 ms) : 0, 351292
GlobalTracer [candidate] (351.205 ms) : 0, 351205
AppSec [baseline] (55.317 ms) : 0, 55317
AppSec [candidate] (54.936 ms) : 0, 54936
Remote Config [baseline] (695.036 µs) : 0, 695
Remote Config [candidate] (673.97 µs) : 0, 674
Telemetry [baseline] (8.97 ms) : 0, 8970
Telemetry [candidate] (8.964 ms) : 0, 8964
ProfilingAgent [baseline] (95.638 ms) : 0, 95638
ProfilingAgent [candidate] (96.24 ms) : 0, 96240
Profiling [baseline] (95.663 ms) : 0, 95663
Profiling [candidate] (96.265 ms) : 0, 96265
Loading

Load

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
end_time 2025-02-14T18:53:08 2025-02-14T19:00:12
git_branch master alejandro.gonzalez/fix-stackId-vulnerabilities
git_commit_date 1739556495 1739558441
git_commit_sha bab17ef c9a71f5
release_version 1.47.0-SNAPSHOT~bab17eff8d 1.47.0-SNAPSHOT~c9a71f54c6
start_time 2025-02-14T18:52:55 2025-02-14T18:59:58
See matching parameters
Baseline Candidate
application insecure-bank insecure-bank
ci_job_date 1739559970 1739559970
ci_job_id 809444947 809444947
ci_pipeline_id 55974654 55974654
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_version Linux runner-hzy35tlz-project-304-concurrent-1-vhpugt9h 6.8.0-1021-aws #23~22.04.1-Ubuntu SMP Tue Dec 10 16:50:46 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux Linux runner-hzy35tlz-project-304-concurrent-1-vhpugt9h 6.8.0-1021-aws #23~22.04.1-Ubuntu SMP Tue Dec 10 16:50:46 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux
variant iast iast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 16 unstable metrics.

Request duration reports for insecure-bank
gantt
    title insecure-bank - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
    dateFormat X
    axisFormat %s
section baseline
no_agent (375.532 µs) : 356, 395
.   : milestone, 376,
iast (503.113 µs) : 482, 525
.   : milestone, 503,
iast_FULL (744.188 µs) : 722, 766
.   : milestone, 744,
iast_GLOBAL (551.709 µs) : 530, 574
.   : milestone, 552,
iast_HARDCODED_SECRET_DISABLED (506.726 µs) : 484, 530
.   : milestone, 507,
iast_INACTIVE (458.146 µs) : 437, 479
.   : milestone, 458,
iast_TELEMETRY_OFF (495.897 µs) : 474, 518
.   : milestone, 496,
tracing (464.773 µs) : 444, 486
.   : milestone, 465,
section candidate
no_agent (374.915 µs) : 355, 395
.   : milestone, 375,
iast (507.869 µs) : 486, 530
.   : milestone, 508,
iast_FULL (740.956 µs) : 719, 763
.   : milestone, 741,
iast_GLOBAL (553.426 µs) : 531, 576
.   : milestone, 553,
iast_HARDCODED_SECRET_DISABLED (505.093 µs) : 483, 527
.   : milestone, 505,
iast_INACTIVE (457.816 µs) : 436, 480
.   : milestone, 458,
iast_TELEMETRY_OFF (494.867 µs) : 472, 518
.   : milestone, 495,
tracing (458.09 µs) : 437, 479
.   : milestone, 458,
Loading
  • baseline results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 375.532 µs [355.577 µs, 395.486 µs] -
iast 503.113 µs [481.638 µs, 524.588 µs] 127.581 µs (34.0%)
iast_FULL 744.188 µs [722.304 µs, 766.072 µs] 368.656 µs (98.2%)
iast_GLOBAL 551.709 µs [529.698 µs, 573.719 µs] 176.177 µs (46.9%)
iast_HARDCODED_SECRET_DISABLED 506.726 µs [483.764 µs, 529.688 µs] 131.194 µs (34.9%)
iast_INACTIVE 458.146 µs [437.091 µs, 479.2 µs] 82.614 µs (22.0%)
iast_TELEMETRY_OFF 495.897 µs [473.824 µs, 517.969 µs] 120.365 µs (32.1%)
tracing 464.773 µs [444.005 µs, 485.542 µs] 89.242 µs (23.8%)
  • candidate results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 374.915 µs [354.929 µs, 394.9 µs] -
iast 507.869 µs [485.96 µs, 529.778 µs] 132.955 µs (35.5%)
iast_FULL 740.956 µs [718.937 µs, 762.975 µs] 366.041 µs (97.6%)
iast_GLOBAL 553.426 µs [531.269 µs, 575.583 µs] 178.511 µs (47.6%)
iast_HARDCODED_SECRET_DISABLED 505.093 µs [482.717 µs, 527.469 µs] 130.178 µs (34.7%)
iast_INACTIVE 457.816 µs [436.089 µs, 479.542 µs] 82.901 µs (22.1%)
iast_TELEMETRY_OFF 494.867 µs [471.694 µs, 518.04 µs] 119.952 µs (32.0%)
tracing 458.09 µs [436.868 µs, 479.312 µs] 83.175 µs (22.2%)
Request duration reports for petclinic
gantt
    title petclinic - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
    dateFormat X
    axisFormat %s
section baseline
no_agent (1.352 ms) : 1333, 1371
.   : milestone, 1352,
appsec (1.72 ms) : 1696, 1743
.   : milestone, 1720,
appsec_no_iast (1.753 ms) : 1730, 1776
.   : milestone, 1753,
iast (1.516 ms) : 1492, 1539
.   : milestone, 1516,
profiling (1.536 ms) : 1511, 1560
.   : milestone, 1536,
tracing (1.502 ms) : 1478, 1526
.   : milestone, 1502,
section candidate
no_agent (1.364 ms) : 1345, 1383
.   : milestone, 1364,
appsec (1.735 ms) : 1711, 1758
.   : milestone, 1735,
appsec_no_iast (1.748 ms) : 1725, 1770
.   : milestone, 1748,
iast (1.511 ms) : 1487, 1534
.   : milestone, 1511,
profiling (1.555 ms) : 1531, 1580
.   : milestone, 1555,
tracing (1.465 ms) : 1439, 1490
.   : milestone, 1465,
Loading
  • baseline results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 1.352 ms [1.333 ms, 1.371 ms] -
appsec 1.72 ms [1.696 ms, 1.743 ms] 367.508 µs (27.2%)
appsec_no_iast 1.753 ms [1.73 ms, 1.776 ms] 400.907 µs (29.6%)
iast 1.516 ms [1.492 ms, 1.539 ms] 163.274 µs (12.1%)
profiling 1.536 ms [1.511 ms, 1.56 ms] 183.196 µs (13.5%)
tracing 1.502 ms [1.478 ms, 1.526 ms] 149.88 µs (11.1%)
  • candidate results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 1.364 ms [1.345 ms, 1.383 ms] -
appsec 1.735 ms [1.711 ms, 1.758 ms] 371.219 µs (27.2%)
appsec_no_iast 1.748 ms [1.725 ms, 1.77 ms] 383.939 µs (28.2%)
iast 1.511 ms [1.487 ms, 1.534 ms] 146.921 µs (10.8%)
profiling 1.555 ms [1.531 ms, 1.58 ms] 191.678 µs (14.1%)
tracing 1.465 ms [1.439 ms, 1.49 ms] 101.08 µs (7.4%)

Dacapo

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
git_branch master alejandro.gonzalez/fix-stackId-vulnerabilities
git_commit_date 1739556495 1739558441
git_commit_sha bab17ef c9a71f5
release_version 1.47.0-SNAPSHOT~bab17eff8d 1.47.0-SNAPSHOT~c9a71f54c6
See matching parameters
Baseline Candidate
application biojava biojava
ci_job_date 1739560420 1739560420
ci_job_id 809444948 809444948
ci_pipeline_id 55974654 55974654
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
kernel_version Linux runner-raydgk-c-project-304-concurrent-1-pv7hyatd 6.8.0-1021-aws #23~22.04.1-Ubuntu SMP Tue Dec 10 16:50:46 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux Linux runner-raydgk-c-project-304-concurrent-1-pv7hyatd 6.8.0-1021-aws #23~22.04.1-Ubuntu SMP Tue Dec 10 16:50:46 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux
variant appsec appsec

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics.

Execution time for biojava
gantt
    title biojava - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
    dateFormat X
    axisFormat %s
section baseline
no_agent (15.484 s) : 15484000, 15484000
.   : milestone, 15484000,
appsec (15.079 s) : 15079000, 15079000
.   : milestone, 15079000,
iast (18.788 s) : 18788000, 18788000
.   : milestone, 18788000,
iast_GLOBAL (18.133 s) : 18133000, 18133000
.   : milestone, 18133000,
profiling (15.852 s) : 15852000, 15852000
.   : milestone, 15852000,
tracing (15.019 s) : 15019000, 15019000
.   : milestone, 15019000,
section candidate
no_agent (15.585 s) : 15585000, 15585000
.   : milestone, 15585000,
appsec (14.926 s) : 14926000, 14926000
.   : milestone, 14926000,
iast (18.952 s) : 18952000, 18952000
.   : milestone, 18952000,
iast_GLOBAL (18.163 s) : 18163000, 18163000
.   : milestone, 18163000,
profiling (15.018 s) : 15018000, 15018000
.   : milestone, 15018000,
tracing (15.111 s) : 15111000, 15111000
.   : milestone, 15111000,
Loading
  • baseline results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 15.484 s [15.484 s, 15.484 s] -
appsec 15.079 s [15.079 s, 15.079 s] -405.0 ms (-2.6%)
iast 18.788 s [18.788 s, 18.788 s] 3.304 s (21.3%)
iast_GLOBAL 18.133 s [18.133 s, 18.133 s] 2.649 s (17.1%)
profiling 15.852 s [15.852 s, 15.852 s] 368.0 ms (2.4%)
tracing 15.019 s [15.019 s, 15.019 s] -465.0 ms (-3.0%)
  • candidate results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 15.585 s [15.585 s, 15.585 s] -
appsec 14.926 s [14.926 s, 14.926 s] -659.0 ms (-4.2%)
iast 18.952 s [18.952 s, 18.952 s] 3.367 s (21.6%)
iast_GLOBAL 18.163 s [18.163 s, 18.163 s] 2.578 s (16.5%)
profiling 15.018 s [15.018 s, 15.018 s] -567.0 ms (-3.6%)
tracing 15.111 s [15.111 s, 15.111 s] -474.0 ms (-3.0%)
Execution time for tomcat
gantt
    title tomcat - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
    dateFormat X
    axisFormat %s
section baseline
no_agent (1.475 ms) : 1463, 1487
.   : milestone, 1475,
appsec (2.377 ms) : 2333, 2421
.   : milestone, 2377,
iast (2.123 ms) : 2068, 2178
.   : milestone, 2123,
iast_GLOBAL (2.159 ms) : 2103, 2214
.   : milestone, 2159,
profiling (2.005 ms) : 1960, 2050
.   : milestone, 2005,
tracing (1.967 ms) : 1924, 2009
.   : milestone, 1967,
section candidate
no_agent (1.479 ms) : 1467, 1490
.   : milestone, 1479,
appsec (2.381 ms) : 2337, 2425
.   : milestone, 2381,
iast (2.12 ms) : 2065, 2175
.   : milestone, 2120,
iast_GLOBAL (2.163 ms) : 2108, 2219
.   : milestone, 2163,
profiling (1.985 ms) : 1941, 2030
.   : milestone, 1985,
tracing (1.964 ms) : 1921, 2006
.   : milestone, 1964,
Loading
  • baseline results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 1.475 ms [1.463 ms, 1.487 ms] -
appsec 2.377 ms [2.333 ms, 2.421 ms] 901.747 µs (61.1%)
iast 2.123 ms [2.068 ms, 2.178 ms] 648.028 µs (43.9%)
iast_GLOBAL 2.159 ms [2.103 ms, 2.214 ms] 683.75 µs (46.4%)
profiling 2.005 ms [1.96 ms, 2.05 ms] 529.577 µs (35.9%)
tracing 1.967 ms [1.924 ms, 2.009 ms] 491.728 µs (33.3%)
  • candidate results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 1.479 ms [1.467 ms, 1.49 ms] -
appsec 2.381 ms [2.337 ms, 2.425 ms] 902.111 µs (61.0%)
iast 2.12 ms [2.065 ms, 2.175 ms] 641.474 µs (43.4%)
iast_GLOBAL 2.163 ms [2.108 ms, 2.219 ms] 684.641 µs (46.3%)
profiling 1.985 ms [1.941 ms, 2.03 ms] 506.67 µs (34.3%)
tracing 1.964 ms [1.921 ms, 2.006 ms] 484.906 µs (32.8%)

@jandro996 jandro996 force-pushed the alejandro.gonzalez/fix-stackId-vulnerabilities branch from 7d1dd4b to d122a05 Compare February 14, 2025 09:10
@jandro996 jandro996 force-pushed the alejandro.gonzalez/fix-stackId-vulnerabilities branch from d122a05 to c9a71f5 Compare February 14, 2025 18:40
@jandro996 jandro996 marked this pull request as ready for review February 17, 2025 06:28
@jandro996 jandro996 requested a review from a team as a code owner February 17, 2025 06:28
@jandro996 jandro996 added the tag: no release notes Changes to exclude from release notes label Feb 17, 2025
@jandro996 jandro996 merged commit 5b9a331 into master Feb 17, 2025
205 checks passed
@jandro996 jandro996 deleted the alejandro.gonzalez/fix-stackId-vulnerabilities branch February 17, 2025 12:40
@github-actions github-actions bot added this to the 1.47.0 milestone Feb 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
comp: asm iast Application Security Management (IAST) tag: no release notes Changes to exclude from release notes type: bug
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants