-
Notifications
You must be signed in to change notification settings - Fork 303
Move stackId from Vulnerability to Location #8384
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
jandro996
merged 1 commit into
master
from
alejandro.gonzalez/fix-stackId-vulnerabilities
Feb 17, 2025
Merged
Move stackId from Vulnerability to Location #8384
jandro996
merged 1 commit into
master
from
alejandro.gonzalez/fix-stackId-vulnerabilities
Feb 17, 2025
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 58 metrics, 5 unstable metrics. Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.045 s) : 0, 1045422
Total [baseline] (8.676 s) : 0, 8675944
Agent [candidate] (1.04 s) : 0, 1039787
Total [candidate] (8.676 s) : 0, 8675763
section iast
Agent [baseline] (1.169 s) : 0, 1169465
Total [baseline] (9.275 s) : 0, 9275372
Agent [candidate] (1.169 s) : 0, 1168790
Total [candidate] (9.246 s) : 0, 9245984
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.179 s) : 0, 1178849
Total [baseline] (9.297 s) : 0, 9296668
Agent [candidate] (1.175 s) : 0, 1175053
Total [candidate] (9.274 s) : 0, 9273911
section iast_TELEMETRY_OFF
Agent [baseline] (1.169 s) : 0, 1169096
Total [baseline] (9.248 s) : 0, 9247996
Agent [candidate] (1.174 s) : 0, 1174291
Total [candidate] (9.277 s) : 0, 9277092
gantt
title insecure-bank - break down per module: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (720.111 ms) : 0, 720111
BytebuddyAgent [candidate] (716.865 ms) : 0, 716865
GlobalTracer [baseline] (241.241 ms) : 0, 241241
GlobalTracer [candidate] (240.055 ms) : 0, 240055
AppSec [baseline] (55.729 ms) : 0, 55729
AppSec [candidate] (55.397 ms) : 0, 55397
Remote Config [baseline] (701.415 µs) : 0, 701
Remote Config [candidate] (691.968 µs) : 0, 692
Telemetry [baseline] (12.38 ms) : 0, 12380
Telemetry [candidate] (11.56 ms) : 0, 11560
section iast
BytebuddyAgent [baseline] (834.958 ms) : 0, 834958
BytebuddyAgent [candidate] (834.733 ms) : 0, 834733
GlobalTracer [baseline] (230.01 ms) : 0, 230010
GlobalTracer [candidate] (229.617 ms) : 0, 229617
AppSec [baseline] (57.245 ms) : 0, 57245
AppSec [candidate] (57.383 ms) : 0, 57383
Remote Config [baseline] (614.007 µs) : 0, 614
Remote Config [candidate] (636.05 µs) : 0, 636
Telemetry [baseline] (8.699 ms) : 0, 8699
Telemetry [candidate] (8.669 ms) : 0, 8669
IAST [baseline] (22.761 ms) : 0, 22761
IAST [candidate] (22.571 ms) : 0, 22571
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (842.755 ms) : 0, 842755
BytebuddyAgent [candidate] (837.719 ms) : 0, 837719
GlobalTracer [baseline] (231.365 ms) : 0, 231365
GlobalTracer [candidate] (232.21 ms) : 0, 232210
AppSec [baseline] (57.093 ms) : 0, 57093
AppSec [candidate] (57.361 ms) : 0, 57361
Remote Config [baseline] (626.687 µs) : 0, 627
Remote Config [candidate] (651.053 µs) : 0, 651
Telemetry [baseline] (8.622 ms) : 0, 8622
Telemetry [candidate] (8.841 ms) : 0, 8841
IAST [baseline] (22.976 ms) : 0, 22976
IAST [candidate] (23.044 ms) : 0, 23044
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (834.217 ms) : 0, 834217
BytebuddyAgent [candidate] (838.97 ms) : 0, 838970
GlobalTracer [baseline] (230.995 ms) : 0, 230995
GlobalTracer [candidate] (230.847 ms) : 0, 230847
AppSec [baseline] (52.662 ms) : 0, 52662
AppSec [candidate] (56.633 ms) : 0, 56633
Remote Config [baseline] (612.976 µs) : 0, 613
Remote Config [candidate] (630.217 µs) : 0, 630
Telemetry [baseline] (8.66 ms) : 0, 8660
Telemetry [candidate] (8.624 ms) : 0, 8624
IAST [baseline] (26.691 ms) : 0, 26691
IAST [candidate] (23.229 ms) : 0, 23229
Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.041 s) : 0, 1041441
Total [baseline] (10.473 s) : 0, 10473447
Agent [candidate] (1.044 s) : 0, 1043663
Total [candidate] (10.5 s) : 0, 10499506
section appsec
Agent [baseline] (1.194 s) : 0, 1193843
Total [baseline] (10.809 s) : 0, 10808808
Agent [candidate] (1.185 s) : 0, 1185413
Total [candidate] (10.812 s) : 0, 10812236
section iast
Agent [baseline] (1.169 s) : 0, 1169004
Total [baseline] (10.999 s) : 0, 10999404
Agent [candidate] (1.172 s) : 0, 1171797
Total [candidate] (11.0 s) : 0, 11000158
section profiling
Agent [baseline] (1.262 s) : 0, 1261854
Total [baseline] (10.894 s) : 0, 10893707
Agent [candidate] (1.261 s) : 0, 1261169
Total [candidate] (10.892 s) : 0, 10892022
gantt
title petclinic - break down per module: candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (717.835 ms) : 0, 717835
BytebuddyAgent [candidate] (721.585 ms) : 0, 721585
GlobalTracer [baseline] (239.9 ms) : 0, 239900
GlobalTracer [candidate] (239.972 ms) : 0, 239972
AppSec [baseline] (55.654 ms) : 0, 55654
AppSec [candidate] (55.367 ms) : 0, 55367
Remote Config [baseline] (695.976 µs) : 0, 696
Remote Config [candidate] (702.633 µs) : 0, 703
Telemetry [baseline] (12.128 ms) : 0, 12128
Telemetry [candidate] (10.768 ms) : 0, 10768
section appsec
BytebuddyAgent [baseline] (741.675 ms) : 0, 741675
BytebuddyAgent [candidate] (736.278 ms) : 0, 736278
GlobalTracer [baseline] (238.767 ms) : 0, 238767
GlobalTracer [candidate] (237.055 ms) : 0, 237055
AppSec [baseline] (178.165 ms) : 0, 178165
AppSec [candidate] (177.083 ms) : 0, 177083
Remote Config [baseline] (671.907 µs) : 0, 672
Remote Config [candidate] (669.224 µs) : 0, 669
Telemetry [baseline] (8.346 ms) : 0, 8346
Telemetry [candidate] (8.294 ms) : 0, 8294
IAST [baseline] (21.821 ms) : 0, 21821
IAST [candidate] (21.531 ms) : 0, 21531
section iast
BytebuddyAgent [baseline] (834.782 ms) : 0, 834782
BytebuddyAgent [candidate] (836.618 ms) : 0, 836618
GlobalTracer [baseline] (230.27 ms) : 0, 230270
GlobalTracer [candidate] (230.722 ms) : 0, 230722
AppSec [baseline] (56.823 ms) : 0, 56823
AppSec [candidate] (57.078 ms) : 0, 57078
Remote Config [baseline] (621.805 µs) : 0, 622
Remote Config [candidate] (626.949 µs) : 0, 627
Telemetry [baseline] (8.644 ms) : 0, 8644
Telemetry [candidate] (8.756 ms) : 0, 8756
IAST [baseline] (22.607 ms) : 0, 22607
IAST [candidate] (22.738 ms) : 0, 22738
section profiling
BytebuddyAgent [baseline] (707.629 ms) : 0, 707629
BytebuddyAgent [candidate] (707.007 ms) : 0, 707007
GlobalTracer [baseline] (351.292 ms) : 0, 351292
GlobalTracer [candidate] (351.205 ms) : 0, 351205
AppSec [baseline] (55.317 ms) : 0, 55317
AppSec [candidate] (54.936 ms) : 0, 54936
Remote Config [baseline] (695.036 µs) : 0, 695
Remote Config [candidate] (673.97 µs) : 0, 674
Telemetry [baseline] (8.97 ms) : 0, 8970
Telemetry [candidate] (8.964 ms) : 0, 8964
ProfilingAgent [baseline] (95.638 ms) : 0, 95638
ProfilingAgent [candidate] (96.24 ms) : 0, 96240
Profiling [baseline] (95.663 ms) : 0, 95663
Profiling [candidate] (96.265 ms) : 0, 96265
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 16 unstable metrics. Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section baseline
no_agent (375.532 µs) : 356, 395
. : milestone, 376,
iast (503.113 µs) : 482, 525
. : milestone, 503,
iast_FULL (744.188 µs) : 722, 766
. : milestone, 744,
iast_GLOBAL (551.709 µs) : 530, 574
. : milestone, 552,
iast_HARDCODED_SECRET_DISABLED (506.726 µs) : 484, 530
. : milestone, 507,
iast_INACTIVE (458.146 µs) : 437, 479
. : milestone, 458,
iast_TELEMETRY_OFF (495.897 µs) : 474, 518
. : milestone, 496,
tracing (464.773 µs) : 444, 486
. : milestone, 465,
section candidate
no_agent (374.915 µs) : 355, 395
. : milestone, 375,
iast (507.869 µs) : 486, 530
. : milestone, 508,
iast_FULL (740.956 µs) : 719, 763
. : milestone, 741,
iast_GLOBAL (553.426 µs) : 531, 576
. : milestone, 553,
iast_HARDCODED_SECRET_DISABLED (505.093 µs) : 483, 527
. : milestone, 505,
iast_INACTIVE (457.816 µs) : 436, 480
. : milestone, 458,
iast_TELEMETRY_OFF (494.867 µs) : 472, 518
. : milestone, 495,
tracing (458.09 µs) : 437, 479
. : milestone, 458,
Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section baseline
no_agent (1.352 ms) : 1333, 1371
. : milestone, 1352,
appsec (1.72 ms) : 1696, 1743
. : milestone, 1720,
appsec_no_iast (1.753 ms) : 1730, 1776
. : milestone, 1753,
iast (1.516 ms) : 1492, 1539
. : milestone, 1516,
profiling (1.536 ms) : 1511, 1560
. : milestone, 1536,
tracing (1.502 ms) : 1478, 1526
. : milestone, 1502,
section candidate
no_agent (1.364 ms) : 1345, 1383
. : milestone, 1364,
appsec (1.735 ms) : 1711, 1758
. : milestone, 1735,
appsec_no_iast (1.748 ms) : 1725, 1770
. : milestone, 1748,
iast (1.511 ms) : 1487, 1534
. : milestone, 1511,
profiling (1.555 ms) : 1531, 1580
. : milestone, 1555,
tracing (1.465 ms) : 1439, 1490
. : milestone, 1465,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section baseline
no_agent (15.484 s) : 15484000, 15484000
. : milestone, 15484000,
appsec (15.079 s) : 15079000, 15079000
. : milestone, 15079000,
iast (18.788 s) : 18788000, 18788000
. : milestone, 18788000,
iast_GLOBAL (18.133 s) : 18133000, 18133000
. : milestone, 18133000,
profiling (15.852 s) : 15852000, 15852000
. : milestone, 15852000,
tracing (15.019 s) : 15019000, 15019000
. : milestone, 15019000,
section candidate
no_agent (15.585 s) : 15585000, 15585000
. : milestone, 15585000,
appsec (14.926 s) : 14926000, 14926000
. : milestone, 14926000,
iast (18.952 s) : 18952000, 18952000
. : milestone, 18952000,
iast_GLOBAL (18.163 s) : 18163000, 18163000
. : milestone, 18163000,
profiling (15.018 s) : 15018000, 15018000
. : milestone, 15018000,
tracing (15.111 s) : 15111000, 15111000
. : milestone, 15111000,
Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~c9a71f54c6, baseline=1.47.0-SNAPSHOT~bab17eff8d
dateFormat X
axisFormat %s
section baseline
no_agent (1.475 ms) : 1463, 1487
. : milestone, 1475,
appsec (2.377 ms) : 2333, 2421
. : milestone, 2377,
iast (2.123 ms) : 2068, 2178
. : milestone, 2123,
iast_GLOBAL (2.159 ms) : 2103, 2214
. : milestone, 2159,
profiling (2.005 ms) : 1960, 2050
. : milestone, 2005,
tracing (1.967 ms) : 1924, 2009
. : milestone, 1967,
section candidate
no_agent (1.479 ms) : 1467, 1490
. : milestone, 1479,
appsec (2.381 ms) : 2337, 2425
. : milestone, 2381,
iast (2.12 ms) : 2065, 2175
. : milestone, 2120,
iast_GLOBAL (2.163 ms) : 2108, 2219
. : milestone, 2163,
profiling (1.985 ms) : 1941, 2030
. : milestone, 1985,
tracing (1.964 ms) : 1921, 2006
. : milestone, 1964,
|
7d1dd4b
to
d122a05
Compare
d122a05
to
c9a71f5
Compare
smola
approved these changes
Feb 17, 2025
manuel-alvarez-alvarez
approved these changes
Feb 17, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
comp: asm iast
Application Security Management (IAST)
tag: no release notes
Changes to exclude from release notes
type: bug
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Does This Do
Move stackId from Vulnerability to Location
Motivation
The RFC specifies that
However, this stackId was incorrectly added to the vulnerability instead of to the Location.
Additional Notes
RFC
Contributor Checklist
type:
and (comp:
orinst:
) labels in addition to any usefull labelsclose
,fix
or any linking keywords when referencing an issue.Use
solves
instead, and assign the PR milestone to the issueJira ticket: APPSEC-56772