-
Notifications
You must be signed in to change notification settings - Fork 293
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Extend vulnerability location data with filename #8334
Draft
sezen-datadog
wants to merge
11
commits into
master
Choose a base branch
from
sezen.leblay/APPSEC-56630-Extend-vulnerability-location-data
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Extend vulnerability location data with filename #8334
sezen-datadog
wants to merge
11
commits into
master
from
sezen.leblay/APPSEC-56630-Extend-vulnerability-location-data
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 59 metrics, 4 unstable metrics. Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.045 s) : 0, 1045451
Total [baseline] (10.533 s) : 0, 10532505
Agent [candidate] (1.049 s) : 0, 1049355
Total [candidate] (10.446 s) : 0, 10445751
section appsec
Agent [baseline] (1.182 s) : 0, 1182079
Total [baseline] (10.711 s) : 0, 10710594
Agent [candidate] (1.184 s) : 0, 1184301
Total [candidate] (10.701 s) : 0, 10700592
section iast
Agent [baseline] (1.17 s) : 0, 1170271
Total [baseline] (10.93 s) : 0, 10930328
Agent [candidate] (1.188 s) : 0, 1188362
Total [candidate] (11.048 s) : 0, 11048090
section profiling
Agent [baseline] (1.272 s) : 0, 1271895
Total [baseline] (10.857 s) : 0, 10857432
Agent [candidate] (1.261 s) : 0, 1261318
Total [candidate] (10.843 s) : 0, 10843165
gantt
title petclinic - break down per module: candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (716.72 ms) : 0, 716720
BytebuddyAgent [candidate] (721.228 ms) : 0, 721228
GlobalTracer [baseline] (244.43 ms) : 0, 244430
GlobalTracer [candidate] (244.036 ms) : 0, 244036
AppSec [baseline] (55.455 ms) : 0, 55455
AppSec [candidate] (55.128 ms) : 0, 55128
Remote Config [baseline] (722.514 µs) : 0, 723
Remote Config [candidate] (726.047 µs) : 0, 726
Telemetry [baseline] (12.874 ms) : 0, 12874
Telemetry [candidate] (12.911 ms) : 0, 12911
section appsec
BytebuddyAgent [baseline] (731.793 ms) : 0, 731793
BytebuddyAgent [candidate] (733.732 ms) : 0, 733732
GlobalTracer [baseline] (239.589 ms) : 0, 239589
GlobalTracer [candidate] (239.797 ms) : 0, 239797
IAST [baseline] (21.709 ms) : 0, 21709
IAST [candidate] (21.855 ms) : 0, 21855
AppSec [baseline] (175.755 ms) : 0, 175755
AppSec [candidate] (175.751 ms) : 0, 175751
Remote Config [baseline] (650.31 µs) : 0, 650
Remote Config [candidate] (652.625 µs) : 0, 653
Telemetry [baseline] (8.257 ms) : 0, 8257
Telemetry [candidate] (8.213 ms) : 0, 8213
section iast
BytebuddyAgent [baseline] (833.105 ms) : 0, 833105
BytebuddyAgent [candidate] (846.398 ms) : 0, 846398
GlobalTracer [baseline] (233.037 ms) : 0, 233037
GlobalTracer [candidate] (236.081 ms) : 0, 236081
IAST [baseline] (22.794 ms) : 0, 22794
IAST [candidate] (23.122 ms) : 0, 23122
AppSec [baseline] (56.812 ms) : 0, 56812
AppSec [candidate] (57.826 ms) : 0, 57826
Remote Config [baseline] (608.348 µs) : 0, 608
Remote Config [candidate] (623.465 µs) : 0, 623
Telemetry [baseline] (8.665 ms) : 0, 8665
Telemetry [candidate] (8.835 ms) : 0, 8835
section profiling
BytebuddyAgent [baseline] (712.36 ms) : 0, 712360
BytebuddyAgent [candidate] (706.173 ms) : 0, 706173
GlobalTracer [baseline] (354.641 ms) : 0, 354641
GlobalTracer [candidate] (353.387 ms) : 0, 353387
AppSec [baseline] (55.793 ms) : 0, 55793
AppSec [candidate] (54.302 ms) : 0, 54302
Remote Config [baseline] (711.176 µs) : 0, 711
Remote Config [candidate] (709.032 µs) : 0, 709
Telemetry [baseline] (8.994 ms) : 0, 8994
Telemetry [candidate] (8.832 ms) : 0, 8832
ProfilingAgent [baseline] (96.777 ms) : 0, 96777
ProfilingAgent [candidate] (95.619 ms) : 0, 95619
Profiling [baseline] (96.8 ms) : 0, 96800
Profiling [candidate] (95.643 ms) : 0, 95643
Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.049 s) : 0, 1049226
Total [baseline] (8.65 s) : 0, 8650171
Agent [candidate] (1.044 s) : 0, 1043976
Total [candidate] (8.617 s) : 0, 8616507
section iast
Agent [baseline] (1.17 s) : 0, 1169776
Total [baseline] (9.19 s) : 0, 9189537
Agent [candidate] (1.174 s) : 0, 1173645
Total [candidate] (9.225 s) : 0, 9224954
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.179 s) : 0, 1178721
Total [baseline] (9.185 s) : 0, 9185468
Agent [candidate] (1.18 s) : 0, 1179626
Total [candidate] (9.198 s) : 0, 9197763
section iast_TELEMETRY_OFF
Agent [baseline] (1.165 s) : 0, 1165326
Total [baseline] (9.186 s) : 0, 9185865
Agent [candidate] (1.168 s) : 0, 1168051
Total [candidate] (9.242 s) : 0, 9242225
gantt
title insecure-bank - break down per module: candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (721.081 ms) : 0, 721081
BytebuddyAgent [candidate] (716.09 ms) : 0, 716090
GlobalTracer [baseline] (244.068 ms) : 0, 244068
GlobalTracer [candidate] (242.93 ms) : 0, 242930
AppSec [baseline] (55.198 ms) : 0, 55198
AppSec [candidate] (54.87 ms) : 0, 54870
Remote Config [baseline] (726.014 µs) : 0, 726
Remote Config [candidate] (712.272 µs) : 0, 712
Telemetry [baseline] (12.881 ms) : 0, 12881
Telemetry [candidate] (14.215 ms) : 0, 14215
section iast
BytebuddyAgent [baseline] (832.681 ms) : 0, 832681
BytebuddyAgent [candidate] (834.619 ms) : 0, 834619
GlobalTracer [baseline] (233.08 ms) : 0, 233080
GlobalTracer [candidate] (233.883 ms) : 0, 233883
IAST [baseline] (22.737 ms) : 0, 22737
IAST [candidate] (22.989 ms) : 0, 22989
AppSec [baseline] (56.8 ms) : 0, 56800
AppSec [candidate] (57.439 ms) : 0, 57439
Remote Config [baseline] (617.737 µs) : 0, 618
Remote Config [candidate] (615.966 µs) : 0, 616
Telemetry [baseline] (8.632 ms) : 0, 8632
Telemetry [candidate] (8.844 ms) : 0, 8844
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (839.582 ms) : 0, 839582
BytebuddyAgent [candidate] (840.033 ms) : 0, 840033
GlobalTracer [baseline] (234.314 ms) : 0, 234314
GlobalTracer [candidate] (234.72 ms) : 0, 234720
IAST [baseline] (23.031 ms) : 0, 23031
IAST [candidate] (22.918 ms) : 0, 22918
AppSec [baseline] (57.056 ms) : 0, 57056
AppSec [candidate] (57.135 ms) : 0, 57135
Remote Config [baseline] (627.161 µs) : 0, 627
Remote Config [candidate] (631.77 µs) : 0, 632
Telemetry [baseline] (8.803 ms) : 0, 8803
Telemetry [candidate] (8.835 ms) : 0, 8835
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (829.436 ms) : 0, 829436
BytebuddyAgent [candidate] (831.507 ms) : 0, 831507
GlobalTracer [baseline] (232.575 ms) : 0, 232575
GlobalTracer [candidate] (233.508 ms) : 0, 233508
IAST [baseline] (24.477 ms) : 0, 24477
IAST [candidate] (26.064 ms) : 0, 26064
AppSec [baseline] (54.331 ms) : 0, 54331
AppSec [candidate] (52.552 ms) : 0, 52552
Remote Config [baseline] (622.322 µs) : 0, 622
Remote Config [candidate] (616.262 µs) : 0, 616
Telemetry [baseline] (8.598 ms) : 0, 8598
Telemetry [candidate] (8.528 ms) : 0, 8528
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 16 unstable metrics. Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section baseline
no_agent (1.363 ms) : 1343, 1383
. : milestone, 1363,
appsec (1.752 ms) : 1728, 1776
. : milestone, 1752,
appsec_no_iast (1.777 ms) : 1753, 1800
. : milestone, 1777,
iast (1.531 ms) : 1507, 1555
. : milestone, 1531,
profiling (1.551 ms) : 1526, 1576
. : milestone, 1551,
tracing (1.49 ms) : 1466, 1514
. : milestone, 1490,
section candidate
no_agent (1.361 ms) : 1341, 1381
. : milestone, 1361,
appsec (1.764 ms) : 1740, 1787
. : milestone, 1764,
appsec_no_iast (1.756 ms) : 1733, 1779
. : milestone, 1756,
iast (1.513 ms) : 1489, 1537
. : milestone, 1513,
profiling (1.527 ms) : 1501, 1552
. : milestone, 1527,
tracing (1.48 ms) : 1455, 1505
. : milestone, 1480,
Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section baseline
no_agent (383.392 µs) : 364, 403
. : milestone, 383,
iast (507.22 µs) : 486, 529
. : milestone, 507,
iast_FULL (746.892 µs) : 725, 769
. : milestone, 747,
iast_GLOBAL (560.494 µs) : 539, 582
. : milestone, 560,
iast_HARDCODED_SECRET_DISABLED (510.788 µs) : 489, 532
. : milestone, 511,
iast_INACTIVE (461.163 µs) : 440, 482
. : milestone, 461,
iast_TELEMETRY_OFF (502.691 µs) : 479, 526
. : milestone, 503,
tracing (458.201 µs) : 437, 479
. : milestone, 458,
section candidate
no_agent (384.133 µs) : 364, 404
. : milestone, 384,
iast (508.85 µs) : 487, 531
. : milestone, 509,
iast_FULL (748.108 µs) : 726, 770
. : milestone, 748,
iast_GLOBAL (570.658 µs) : 548, 594
. : milestone, 571,
iast_HARDCODED_SECRET_DISABLED (507.805 µs) : 486, 529
. : milestone, 508,
iast_INACTIVE (461.18 µs) : 440, 482
. : milestone, 461,
iast_TELEMETRY_OFF (501.802 µs) : 478, 525
. : milestone, 502,
tracing (457.094 µs) : 436, 478
. : milestone, 457,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section baseline
no_agent (1.472 ms) : 1461, 1483
. : milestone, 1472,
appsec (2.366 ms) : 2323, 2409
. : milestone, 2366,
iast (2.111 ms) : 2056, 2166
. : milestone, 2111,
iast_GLOBAL (2.156 ms) : 2100, 2211
. : milestone, 2156,
profiling (1.96 ms) : 1917, 2003
. : milestone, 1960,
tracing (1.948 ms) : 1905, 1990
. : milestone, 1948,
section candidate
no_agent (1.469 ms) : 1458, 1481
. : milestone, 1469,
appsec (2.367 ms) : 2323, 2410
. : milestone, 2367,
iast (2.111 ms) : 2056, 2166
. : milestone, 2111,
iast_GLOBAL (2.157 ms) : 2102, 2212
. : milestone, 2157,
profiling (1.966 ms) : 1923, 2009
. : milestone, 1966,
tracing (1.942 ms) : 1900, 1984
. : milestone, 1942,
Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.47.0-SNAPSHOT~b4052d5cd7, baseline=1.47.0-SNAPSHOT~8a74e85918
dateFormat X
axisFormat %s
section baseline
no_agent (15.138 s) : 15138000, 15138000
. : milestone, 15138000,
appsec (15.256 s) : 15256000, 15256000
. : milestone, 15256000,
iast (18.533 s) : 18533000, 18533000
. : milestone, 18533000,
iast_GLOBAL (18.201 s) : 18201000, 18201000
. : milestone, 18201000,
profiling (15.156 s) : 15156000, 15156000
. : milestone, 15156000,
tracing (14.736 s) : 14736000, 14736000
. : milestone, 14736000,
section candidate
no_agent (15.076 s) : 15076000, 15076000
. : milestone, 15076000,
appsec (15.049 s) : 15049000, 15049000
. : milestone, 15049000,
iast (19.114 s) : 19114000, 19114000
. : milestone, 19114000,
iast_GLOBAL (18.023 s) : 18023000, 18023000
. : milestone, 18023000,
profiling (15.238 s) : 15238000, 15238000
. : milestone, 15238000,
tracing (14.686 s) : 14686000, 14686000
. : milestone, 14686000,
|
dd-java-agent/agent-iast/src/main/java/com/datadog/iast/model/VulnerabilityType.java
Show resolved
Hide resolved
…VulnerabilityType.java Co-authored-by: datadog-datadog-prod-us1[bot] <88084959+datadog-datadog-prod-us1[bot]@users.noreply.github.com>
…lity-location-data
dd-java-agent/agent-iast/src/main/java/com/datadog/iast/model/VulnerabilityType.java
Outdated
Show resolved
Hide resolved
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
comp: asm iast
Application Security Management (IAST)
tag: do not merge
Do not merge changes
type: enhancement
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Does This Do
Enhances location with class name for vulnerabilities and changes path to the actual path value (previously class name was stored in this field)
Motivation
Better define location data for vulnerabilities
Additional Notes
Contributor Checklist
type:
and (comp:
orinst:
) labels in addition to any usefull labelsclose
,fix
or any linking keywords when referencing an issue.Use
solves
instead, and assign the PR milestone to the issueJira ticket: APPSEC-56630