I have implemented a step in my pipeline which runs the dependency scanner tool to check my project; it generates a JSON and an HTML report and should generate the CodeInsights report by (default).
- step: &dependency-check
name: Run Dependency Check
script:
- if [ -z "$NVD_API_KEY" ]; then echo "NVD_API_KEY is required"; exit 1; fi
- pipe: atlassian/bitbucket-dependency-scanner:0.1.3
variables:
NVD_API_KEY: $NVD_API_KEY
EXTRA_ARGS:
- "--format=HTML"
- "--failOnCVSS=7"
artifacts:
- dependency-check-report.json
- dependency-check-report.html
However, despite the dependency-check-report.json file being generated, I consistently get an error when the CodeInsights Report is attempting to be generated. I am able to get the reports in my list of artefacts, but the report doesn't appear in the reports tab, and the step fails in the pipeline.
[INFO] Analysis Started
[INFO] Finished File Name Analyzer (0 seconds)
[INFO] Finished Nuspec Analyzer (0 seconds)
[INFO] Finished MSBuild Project Analyzer (0 seconds)
[INFO] Finished Dependency Merging Analyzer (0 seconds)
[INFO] Finished Hint Analyzer (0 seconds)
[INFO] Finished Version Filter Analyzer (0 seconds)
[INFO] Created CPE Index (1 seconds)
[INFO] Finished NPM CPE Analyzer (1 seconds)
[INFO] Created CPE Index (1 seconds)
[INFO] Finished CPE Analyzer (2 seconds)
[INFO] Finished False Positive Analyzer (0 seconds)
[INFO] Finished NVD CVE Analyzer (0 seconds)
[INFO] Finished Sonatype OSS Index Analyzer (0 seconds)
[INFO] Finished Vulnerability Suppression Analyzer (0 seconds)
[INFO] Finished Known Exploited Vulnerability Analyzer (0 seconds)
[INFO] Finished Dependency Bundling Analyzer (0 seconds)
[INFO] Suppression Rule had zero matches: SuppressionRule{packageUrl=PropertyType{value=^pkg:maven/io\.etcd/jetcd-[a-z]*@.*$, regex=true, caseSensitive=false},cpe={PropertyType{value=cpe:/a:redhat:etcd, regex=false, caseSensitive=false},PropertyType{value=cpe:/a:etcd:etcd, regex=false, caseSensitive=false},}}
[INFO] Suppression Rule had zero matches: SuppressionRule{packageUrl=PropertyType{value=^pkg:maven/io\.etcd/jetcd-grpc@.*$, regex=true, caseSensitive=false},cpe={PropertyType{value=cpe:/a:grpc:grpc, regex=false, caseSensitive=false},}}
[INFO] Finished Unused Suppression Rule Analyzer (0 seconds)
[INFO] Analysis Complete (4 seconds)
[INFO] Writing JSON report to: /opt/atlassian/pipelines/agent/build/reports/dependency-check-report.json
[INFO] Writing HTML report to: /opt/atlassian/pipelines/agent/build/reports/dependency-check-report.html
INFO: None
INFO: Generating CodeInsights reports...
INFO: Loading the scanner's results ./reports/dependency-check-report.json
Traceback (most recent call last):
File "/pipe.py", line 226, in
pipe.run()
File "/pipe.py", line 214, in run
self.create_code_insights_report()
File "/pipe.py", line 56, in create_code_insights_report
report_id = self.create_report(results_data)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
TypeError: 'bool' object is not callable
I have tried to use an alternative directory structure, as well as not directory and kept the settings as default to generate the files in the root, but nothing seems to be working to get past this error, which seems to have an issue with loading the specified file and generating the report. Any help appreciated.