-
Notifications
You must be signed in to change notification settings - Fork 278
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add builder for vulnerability types and fix insecure auth protocol #7216
Add builder for vulnerability types and fix insecure auth protocol #7216
Conversation
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 50 metrics, 13 unstable metrics. Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.064 s) : 0, 1063861
Total [baseline] (10.415 s) : 0, 10415283
Agent [candidate] (1.069 s) : 0, 1068521
Total [candidate] (10.425 s) : 0, 10424705
section appsec
Agent [baseline] (1.181 s) : 0, 1180841
Total [baseline] (10.497 s) : 0, 10496939
Agent [candidate] (1.183 s) : 0, 1183333
Total [candidate] (10.487 s) : 0, 10486884
section iast
Agent [baseline] (1.176 s) : 0, 1176242
Total [baseline] (10.706 s) : 0, 10705724
Agent [candidate] (1.17 s) : 0, 1169741
Total [candidate] (10.741 s) : 0, 10740633
section profiling
Agent [baseline] (1.259 s) : 0, 1258962
Total [baseline] (10.591 s) : 0, 10591477
Agent [candidate] (1.261 s) : 0, 1261063
Total [candidate] (10.658 s) : 0, 10658379
gantt
title petclinic - break down per module: candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (666.354 ms) : 0, 666354
BytebuddyAgent [candidate] (669.964 ms) : 0, 669964
GlobalTracer [baseline] (304.512 ms) : 0, 304512
GlobalTracer [candidate] (305.534 ms) : 0, 305534
AppSec [baseline] (50.267 ms) : 0, 50267
AppSec [candidate] (50.174 ms) : 0, 50174
Remote Config [baseline] (685.719 µs) : 0, 686
Remote Config [candidate] (691.736 µs) : 0, 692
Telemetry [baseline] (7.514 ms) : 0, 7514
Telemetry [candidate] (7.523 ms) : 0, 7523
section appsec
BytebuddyAgent [baseline] (675.121 ms) : 0, 675121
BytebuddyAgent [candidate] (677.583 ms) : 0, 677583
GlobalTracer [baseline] (297.163 ms) : 0, 297163
GlobalTracer [candidate] (297.746 ms) : 0, 297746
AppSec [baseline] (153.666 ms) : 0, 153666
AppSec [candidate] (154.026 ms) : 0, 154026
Remote Config [baseline] (637.229 µs) : 0, 637
Remote Config [candidate] (634.397 µs) : 0, 634
Telemetry [baseline] (9.075 ms) : 0, 9075
Telemetry [candidate] (7.195 ms) : 0, 7195
IAST [baseline] (21.585 ms) : 0, 21585
IAST [candidate] (23.134 ms) : 0, 23134
section iast
BytebuddyAgent [baseline] (783.774 ms) : 0, 783774
BytebuddyAgent [candidate] (779.393 ms) : 0, 779393
GlobalTracer [baseline] (295.101 ms) : 0, 295101
GlobalTracer [candidate] (293.084 ms) : 0, 293084
AppSec [baseline] (47.257 ms) : 0, 47257
AppSec [candidate] (47.138 ms) : 0, 47138
Remote Config [baseline] (626.093 µs) : 0, 626
Remote Config [candidate] (720.699 µs) : 0, 721
Telemetry [baseline] (6.936 ms) : 0, 6936
Telemetry [candidate] (7.817 ms) : 0, 7817
IAST [baseline] (29.207 ms) : 0, 29207
IAST [candidate] (28.29 ms) : 0, 28290
section profiling
BytebuddyAgent [baseline] (661.497 ms) : 0, 661497
BytebuddyAgent [candidate] (661.347 ms) : 0, 661347
GlobalTracer [baseline] (384.902 ms) : 0, 384902
GlobalTracer [candidate] (385.256 ms) : 0, 385256
AppSec [baseline] (51.184 ms) : 0, 51184
AppSec [candidate] (51.854 ms) : 0, 51854
Remote Config [baseline] (744.032 µs) : 0, 744
Remote Config [candidate] (733.412 µs) : 0, 733
Telemetry [baseline] (7.352 ms) : 0, 7352
Telemetry [candidate] (7.381 ms) : 0, 7381
ProfilingAgent [baseline] (96.451 ms) : 0, 96451
ProfilingAgent [candidate] (97.76 ms) : 0, 97760
Profiling [baseline] (96.475 ms) : 0, 96475
Profiling [candidate] (97.785 ms) : 0, 97785
Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.061 s) : 0, 1061343
Total [baseline] (8.531 s) : 0, 8530951
Agent [candidate] (1.062 s) : 0, 1062346
Total [candidate] (8.55 s) : 0, 8550407
section iast
Agent [baseline] (1.169 s) : 0, 1168849
Total [baseline] (9.061 s) : 0, 9061370
Agent [candidate] (1.179 s) : 0, 1178917
Total [candidate] (9.015 s) : 0, 9014606
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.167 s) : 0, 1167010
Total [baseline] (9.012 s) : 0, 9011685
Agent [candidate] (1.18 s) : 0, 1180135
Total [candidate] (9.034 s) : 0, 9033594
section iast_TELEMETRY_OFF
Agent [baseline] (1.165 s) : 0, 1164857
Total [baseline] (8.981 s) : 0, 8980832
Agent [candidate] (1.167 s) : 0, 1166951
Total [candidate] (9.004 s) : 0, 9003747
gantt
title insecure-bank - break down per module: candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (665.417 ms) : 0, 665417
BytebuddyAgent [candidate] (665.874 ms) : 0, 665874
GlobalTracer [baseline] (303.081 ms) : 0, 303081
GlobalTracer [candidate] (303.601 ms) : 0, 303601
AppSec [baseline] (50.267 ms) : 0, 50267
AppSec [candidate] (50.146 ms) : 0, 50146
Remote Config [baseline] (693.81 µs) : 0, 694
Remote Config [candidate] (730.436 µs) : 0, 730
Telemetry [baseline] (7.558 ms) : 0, 7558
Telemetry [candidate] (7.583 ms) : 0, 7583
section iast
BytebuddyAgent [baseline] (778.899 ms) : 0, 778899
BytebuddyAgent [candidate] (787.559 ms) : 0, 787559
GlobalTracer [baseline] (293.162 ms) : 0, 293162
GlobalTracer [candidate] (296.124 ms) : 0, 296124
AppSec [baseline] (46.921 ms) : 0, 46921
AppSec [candidate] (47.434 ms) : 0, 47434
Remote Config [baseline] (625.316 µs) : 0, 625
Remote Config [candidate] (617.611 µs) : 0, 618
Telemetry [baseline] (8.44 ms) : 0, 8440
Telemetry [candidate] (7.839 ms) : 0, 7839
IAST [baseline] (27.527 ms) : 0, 27527
IAST [candidate] (25.971 ms) : 0, 25971
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (777.973 ms) : 0, 777973
BytebuddyAgent [candidate] (787.074 ms) : 0, 787074
GlobalTracer [baseline] (292.837 ms) : 0, 292837
GlobalTracer [candidate] (295.624 ms) : 0, 295624
AppSec [baseline] (47.306 ms) : 0, 47306
AppSec [candidate] (47.738 ms) : 0, 47738
Remote Config [baseline] (632.946 µs) : 0, 633
Remote Config [candidate] (726.798 µs) : 0, 727
Telemetry [baseline] (6.925 ms) : 0, 6925
Telemetry [candidate] (6.995 ms) : 0, 6995
IAST [baseline] (28.028 ms) : 0, 28028
IAST [candidate] (28.49 ms) : 0, 28490
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (775.909 ms) : 0, 775909
BytebuddyAgent [candidate] (777.52 ms) : 0, 777520
GlobalTracer [baseline] (293.198 ms) : 0, 293198
GlobalTracer [candidate] (293.58 ms) : 0, 293580
AppSec [baseline] (47.029 ms) : 0, 47029
AppSec [candidate] (47.137 ms) : 0, 47137
Remote Config [baseline] (607.131 µs) : 0, 607
Remote Config [candidate] (595.956 µs) : 0, 596
Telemetry [baseline] (8.462 ms) : 0, 8462
Telemetry [candidate] (6.809 ms) : 0, 6809
IAST [baseline] (26.355 ms) : 0, 26355
IAST [candidate] (27.984 ms) : 0, 27984
LoadParameters
See matching parameters
SummaryFound 1 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 16 unstable metrics.
Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section baseline
no_agent (377.046 µs) : 358, 397
. : milestone, 377,
iast (492.39 µs) : 471, 514
. : milestone, 492,
iast_FULL (549.797 µs) : 528, 571
. : milestone, 550,
iast_GLOBAL (517.175 µs) : 494, 540
. : milestone, 517,
iast_HARDCODED_SECRET_DISABLED (485.366 µs) : 464, 507
. : milestone, 485,
iast_INACTIVE (453.971 µs) : 433, 475
. : milestone, 454,
iast_TELEMETRY_OFF (475.783 µs) : 454, 497
. : milestone, 476,
tracing (447.952 µs) : 427, 469
. : milestone, 448,
section candidate
no_agent (365.866 µs) : 346, 386
. : milestone, 366,
iast (487.148 µs) : 466, 508
. : milestone, 487,
iast_FULL (560.123 µs) : 539, 582
. : milestone, 560,
iast_GLOBAL (510.482 µs) : 489, 531
. : milestone, 510,
iast_HARDCODED_SECRET_DISABLED (483.559 µs) : 462, 505
. : milestone, 484,
iast_INACTIVE (459.78 µs) : 438, 481
. : milestone, 460,
iast_TELEMETRY_OFF (478.727 µs) : 457, 500
. : milestone, 479,
tracing (453.673 µs) : 432, 475
. : milestone, 454,
Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section baseline
no_agent (1.349 ms) : 1329, 1369
. : milestone, 1349,
appsec (1.735 ms) : 1711, 1759
. : milestone, 1735,
appsec_no_iast (1.728 ms) : 1703, 1753
. : milestone, 1728,
iast (1.489 ms) : 1467, 1510
. : milestone, 1489,
profiling (1.556 ms) : 1531, 1581
. : milestone, 1556,
tracing (1.46 ms) : 1435, 1485
. : milestone, 1460,
section candidate
no_agent (1.354 ms) : 1335, 1373
. : milestone, 1354,
appsec (1.737 ms) : 1713, 1762
. : milestone, 1737,
appsec_no_iast (1.721 ms) : 1696, 1746
. : milestone, 1721,
iast (1.476 ms) : 1453, 1499
. : milestone, 1476,
profiling (1.491 ms) : 1467, 1516
. : milestone, 1491,
tracing (1.464 ms) : 1439, 1488
. : milestone, 1464,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section baseline
no_agent (14.968 s) : 14968000, 14968000
. : milestone, 14968000,
appsec (15.001 s) : 15001000, 15001000
. : milestone, 15001000,
iast (18.78 s) : 18780000, 18780000
. : milestone, 18780000,
iast_GLOBAL (17.826 s) : 17826000, 17826000
. : milestone, 17826000,
profiling (16.364 s) : 16364000, 16364000
. : milestone, 16364000,
tracing (14.891 s) : 14891000, 14891000
. : milestone, 14891000,
section candidate
no_agent (14.775 s) : 14775000, 14775000
. : milestone, 14775000,
appsec (14.864 s) : 14864000, 14864000
. : milestone, 14864000,
iast (18.801 s) : 18801000, 18801000
. : milestone, 18801000,
iast_GLOBAL (17.918 s) : 17918000, 17918000
. : milestone, 17918000,
profiling (15.148 s) : 15148000, 15148000
. : milestone, 15148000,
tracing (14.92 s) : 14920000, 14920000
. : milestone, 14920000,
Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.36.0-SNAPSHOT~4ee55caddd, baseline=1.36.0-SNAPSHOT~ae0ed76333
dateFormat X
axisFormat %s
section baseline
no_agent (1.46 ms) : 1449, 1472
. : milestone, 1460,
appsec (2.211 ms) : 2177, 2245
. : milestone, 2211,
iast (1.965 ms) : 1923, 2006
. : milestone, 1965,
iast_GLOBAL (2.005 ms) : 1965, 2046
. : milestone, 2005,
profiling (1.857 ms) : 1821, 1892
. : milestone, 1857,
tracing (1.827 ms) : 1795, 1858
. : milestone, 1827,
section candidate
no_agent (1.461 ms) : 1450, 1473
. : milestone, 1461,
appsec (2.209 ms) : 2175, 2244
. : milestone, 2209,
iast (1.958 ms) : 1918, 1998
. : milestone, 1958,
iast_GLOBAL (2.009 ms) : 1968, 2050
. : milestone, 2009,
profiling (1.844 ms) : 1811, 1877
. : milestone, 1844,
tracing (1.827 ms) : 1795, 1860
. : milestone, 1827,
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Much better with the Builder!
What Does This Do
Refactor
VulnerabilityType
constructor and fixINSECURE_AUTH_PROTOCOL
hash.Motivation
The hashing of the
INSECURE_AUTH_PROTOCOL
was using file and line when it should use the evidence to compute the hash.Additional Notes
Jira ticket: [PROJ-IDENT]
Specification