Merge pull request #225 from AikidoSec/fix-shell-injection #29
qa-tests.yml
on: push
build-package
7m 47s
qa-tests
6m 19s
Annotations
10 errors and 10 warnings
|
qa-tests
2026-01-29 08:56:30,363 - ERROR - Error in test test_stored_ssrf_no_context: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_stored_ssrf_no_context/test.py", line 49, in check_ssrf_with_event<br>`AssertionError: Status codes are not the same, expected 200, got 404 - []`
|
|
qa-tests
2026-01-29 08:56:30,181 - ERROR - Error running test: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_stored_ssrf_no_context/test.py", line 49, in check_ssrf_with_event<br>`AssertionError: Status codes are not the same, expected 200, got 404 - []`
|
|
qa-tests
2026-01-29 08:56:10,947 - ERROR - Error in test test_path_traversal: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_path_traversal/test.py", line 36, in check_path_traversal<br>`AssertionError: Status code should be different from 200. Message: Path traversal check failed for /api/read2?path=../secrets/key.txt {C0d3_Br3ak3r_4_L1f3!}`
|
|
qa-tests
2026-01-29 08:56:10,755 - ERROR - Error running test: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_path_traversal/test.py", line 36, in check_path_traversal<br>`AssertionError: Status code should be different from 200. Message: Path traversal check failed for /api/read2?path=../secrets/key.txt {C0d3_Br3ak3r_4_L1f3!}`
|
|
qa-tests
2026-01-29 08:56:10,140 - ERROR - Error in test test_ssrf: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_ssrf/test.py", line 77, in check_ssrf_with_event<br>`AssertionError: Status codes are not the same, expected 500, got 200 - None`
|
|
qa-tests
2026-01-29 08:56:09,930 - ERROR - Error running test: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_ssrf/test.py", line 77, in check_ssrf_with_event<br>`AssertionError: Status codes are not the same, expected 500, got 200 - None`
|
|
qa-tests
2026-01-29 08:55:32,790 - ERROR - Error in test test_force_protection_off: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_force_protection_off/test.py", line 16, in check_force_protection_off<br>`AssertionError: Status codes are not the same, expected 200, got 500 - shell injection`
|
|
qa-tests
2026-01-29 08:55:32,602 - ERROR - Error running test: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_force_protection_off/test.py", line 16, in check_force_protection_off<br>`AssertionError: Status codes are not the same, expected 200, got 500 - shell injection`
|
|
qa-tests
2026-01-29 08:54:18,699 - ERROR - Error in test test_stored_ssrf: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_stored_ssrf/test.py", line 73, in check_ssrf_with_event<br>`AssertionError: Status codes are not the same, expected 500, got 404 - []`
|
|
qa-tests
2026-01-29 08:54:18,511 - ERROR - Error running test: File "/home/runner/work/_actions/AikidoSec/firewall-tester-action/v1.0.7/server_tests/test_stored_ssrf/test.py", line 73, in check_ssrf_with_event<br>`AssertionError: Status codes are not the same, expected 500, got 404 - []`
|
|
build-package:
Aikido.Zen.Test/ConcurrentLFUDictionaryTests.cs#L26
Nullability of type of parameter 'obj' doesn't match overridden member (possibly because of nullability attributes).
|
|
build-package
Targeting .NET 10.0 or higher in Visual Studio 2022 17.14 is not supported.
|
|
build-package:
Aikido.Zen.DotNetCore/Zen.cs#L11
Field 'Zen._httpContextAccessor' is never assigned to, and will always have its default value null
|
|
build-package
Targeting .NET 10.0 or higher in Visual Studio 2022 17.14 is not supported.
|
|
build-package:
Aikido.Zen.DotNetCore/Zen.cs#L11
Field 'Zen._httpContextAccessor' is never assigned to, and will always have its default value null
|
|
build-package:
Aikido.Zen.DotNetCore/Zen.cs#L11
Field 'Zen._httpContextAccessor' is never assigned to, and will always have its default value null
|
|
build-package:
Aikido.Zen.DotNetCore/Zen.cs#L11
Field 'Zen._httpContextAccessor' is never assigned to, and will always have its default value null
|
|
build-package:
Aikido.Zen.DotNetCore/Zen.cs#L11
Field 'Zen._httpContextAccessor' is never assigned to, and will always have its default value null
|
|
build-package:
Aikido.Zen.Core/Agent.cs#L264
The variable 'ex' is declared but never used
|
|
build-package:
Aikido.Zen.Core/Agent.cs#L143
Because this call is not awaited, execution of the current method continues before the call is completed. Consider applying the 'await' operator to the result of the call.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
nuget-package
|
42.6 MB |
sha256:06d84cad626b00cbcf1eb32131ca8f3aed7373da5f8ab891b1a42b97357cd9e2
|
|