Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cannot create ignore rules for specific watch #288

Open
8L4ckc0FF33 opened this issue Feb 13, 2023 · 2 comments
Open

Cannot create ignore rules for specific watch #288

8L4ckc0FF33 opened this issue Feb 13, 2023 · 2 comments
Labels
bug Something isn't working

Comments

@8L4ckc0FF33
Copy link

Describe the bug

Hi there,

I want to set an ignore rule from within the Jfrog IDEA Plugin, but it does not work the way I expect. It opens the input mask for ignore rules in the browser on my Xray installation (with an error: 'could not parse user_issue_id') but there's no watch pre-selected nor is there any watch in the drop down list. So cannot create an ignore rule attached to the watch for the project (although the watch is part of the GET-parameters in the URL: graph_scan_id, issue_id, show_popup, type, watch_name). When creating the ignore rule it can only be done globally for all projects. But in my opinion that's not feasible, since a vulnerability is not equally critical for each project.

When using the UI it's possible to create ignore rules for each watch.

Maybe I didn't figure out how to configure Jfrog Xray and its Intellij Idea Plugin correctly or is it a bug?

To Reproduce

Connecting Jfrog IDEA Plugin to a watch. Let the plugin index the project. Right click on any violation and choose "create ignore rule" and letting the browser open the input mask on your Xray-installation. And there's no possibility to choose any watch (screenshot).

With Crtl+Alt+S -> Other Settings -> Jfrog Global Configuration i filled out:
Connection Details:

Settings:

  • Project Key
  • Scanning Policy -> According to Watchs: my.security.watch, my.licence.watch

Advanced

  • Connection retries: 3
  • Connection timeout: 60
  • Excluded path:

Expected behavior

When creating an ignore rule from within IDEA it should be possible to connect this ignore rule to the watch with witch it is connected in the settings.
Actually I'd expect the same behaviour as clicking in the UI -> Xray -> Watch Violations -> Create Vulnerability Ignore Rule

Screenshots

xray_ignore

Versions

  • Windows 10
  • Intellij IDEA 2022.2.3
  • Jfrog Plugin 1.16.6
  • Xray: 3.66.6
@8L4ckc0FF33 8L4ckc0FF33 added the bug Something isn't working label Feb 13, 2023
@yahavi
Copy link
Member

yahavi commented Feb 14, 2023

@8L4ckc0FF33,
Thanks for reporting this issue. We are looking into it.
We'll keep you updated about that issue here.

@8L4ckc0FF33
Copy link
Author

Hi, is there any progress on this issue?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants