Running with gitlab-runner 13.2.0 (353dd94e)  on global-shared-gitlab-runner-8dd6b4777-87gcx dPJcxnQf section_start:1601420582:prepare_executor Preparing the "kubernetes" executor Using Kubernetes namespace: gitlab-runner Using Kubernetes executor with image ${GITLAB_INTERNAL_REGISTRY}/ironbank-tools/ironbank-pipeline/jenkins-oscap-agent:1.1 ... section_end:1601420582:prepare_executor section_start:1601420582:prepare_script Preparing environment Waiting for pod gitlab-runner/runner-dpjcxnqf-project-701-concurrent-0vmwgn to be running, status is Pending Running on runner-dpjcxnqf-project-701-concurrent-0vmwgn via global-shared-gitlab-runner-8dd6b4777-87gcx... section_end:1601420586:prepare_script section_start:1601420586:get_sources Getting source from Git repository Fetching changes with git depth set to 50... Initialized empty Git repository in /builds/dsop/coder-enterprise/coder-enterprise/timescale/.git/ Created fresh repository. Checking out 0ebbd133 as development... Skipping Git submodules setup section_end:1601420586:get_sources section_start:1601420586:download_artifacts Downloading artifacts Downloading artifacts for anchore scan (340715)... Dialing: tcp gitlab-webservice.gitlab.svc.cluster.local:8181 ... Downloading artifacts from coordinator... ok  id=340715 responseStatus=200 OK token=v2ixENma Downloading artifacts for load scripts (340705)... Dialing: tcp gitlab-webservice.gitlab.svc.cluster.local:8181 ... Downloading artifacts from coordinator... ok  id=340705 responseStatus=200 OK token=N1hQkL92 Downloading artifacts for openscap compliance (340712)... Dialing: tcp gitlab-webservice.gitlab.svc.cluster.local:8181 ... Downloading artifacts from coordinator... ok  id=340712 responseStatus=200 OK token=nkY1uaAZ Downloading artifacts for openscap cve (340713)... Dialing: tcp gitlab-webservice.gitlab.svc.cluster.local:8181 ... Downloading artifacts from coordinator... ok  id=340713 responseStatus=200 OK token=9ubLcfqo Downloading artifacts for twistlock scan (340714)... Dialing: tcp gitlab-webservice.gitlab.svc.cluster.local:8181 ... Downloading artifacts from coordinator... ok  id=340714 responseStatus=200 OK token=NhF2Aun- section_end:1601420587:download_artifacts section_start:1601420587:step_script Executing "step_script" stage of the job script $ repo_path="${CI_PROJECT_DIR}" $ wl_image_path=$(echo ${CI_PROJECT_PATH} | sed -e 's/.*dsop\/\(.*\)/\1/') $ python3 ${PIPELINE_REPO_DIR}/stages/check-cves/pipeline_wl_compare.py --image ${wl_image_path} --tag ${IMG_VERSION} --oscap ${ARTIFACT_STORAGE}/scan-results/openscap/report.html --oval ${ARTIFACT_STORAGE}/scan-results/openscap/report-cve.html --twistlock ${ARTIFACT_STORAGE}/scan-results/twistlock/${IMG_VERSION}.json --anchore-sec ${ARTIFACT_STORAGE}/scan-results/anchore/anchore_security.json --anchore-gates ${ARTIFACT_STORAGE}/scan-results/anchore/anchore_gates.json --glkey "${PYTHON_GL_KEY}" --proj_branch "${CI_COMMIT_BRANCH}" --wl_branch "${WL_TARGET_BRANCH}" Fetching Whitelisted CVEs from parent: redhat/ubi/ubi7:7.8 Whitelist Set: {'CCE-80533-3', 'CVE-2019-5188', 'VULNDB-108369', 'VULNDB-200148', 'CVE-2015-8982', 'VULNDB-217762', 'CCE-80438-5', 'CVE-2014-4617', 'CVE-2019-17023', 'CVE-2014-9939', 'CCE-27157-7', 'CVE-2013-7040', 'CVE-2014-3637', 'CVE-2016-1000110', 'CVE-2020-12399', 'CVE-2019-19956', 'CVE-2020-24977', 'CVE-2014-4043', 'CVE-2013-7440', 'e7573262736ef52353cde3bae2617782', 'CVE-2019-20388', 'CVE-2019-20907', 'CVE-2019-16935', 'CVE-2019-18276', 'CVE-2019-5010', 'CVE-2019-17450', 'CVE-2020-12403', 'CVE-2015-4042', 'CCE-80534-1', '34de21e516c0ca50a96e5386f163f8bf', 'CCE-80530-9', 'CVE-2015-8983', 'CVE-2018-16428', 'CVE-2019-3842', 'CVE-2018-1000030', 'CVE-2017-18207', 'CVE-2014-4616', 'CVE-2020-12243', 'CCE-80529-1', 'CVE-2020-12413', '41cb7cdf04850e33a11f80c42bf660b3', 'VULNDB-137890', 'CVE-2016-0772', 'CCE-26884-7', 'CVE-2019-17006', 'CVE-2013-1753', 'CVE-2018-9234', 'CVE-2019-11756', 'abb121e9621abdd452f65844954cf1c1', 'CVE-2017-17522', 'CCE-27209-6', 'CCE-80532-5', 'CVE-2019-17498', 'CVE-2014-9365', '639f6f1177735759703e928c14714a59', 'CVE-2015-5652', 'CVE-2020-12402', 'ad4759bf9c3ce28f10d9d2f6eae51fa1', 'CVE-2019-9633', 'CVE-2020-12401', 'CVE-2014-7185', '320a97c6816565eedf3545833df99dd0', 'CVE-2019-18197', 'c4ad80832b361f81df2a31e5b6b09864', 'CCE-80522-6', 'CCE-80536-6', 'bcd159901fe47efddae5c095b4b0d7fd', 'CCE-80526-7', 'CCE-80524-2', 'CVE-2014-1912', 'CCE-80535-8', 'CVE-2020-8177', 'c67a2c13ebe88380113e7fbcb2437714', '3e5fad1c039f3ecfd1dcdc94d2f1f9a0', 'CVE-2019-9169', 'CVE-2019-18348', 'CVE-2020-7595', 'CVE-2014-3635', 'CVE-2020-14155', 'CCE-80134-0', 'CVE-2016-5636', 'CVE-2018-16429', 'CCE-26895-3', 'CCE-80521-8', '3456a263793066e9b5063ada6e47917d', 'CVE-2018-6954', 'CVE-2019-9948', 'CCE-80531-7', 'CVE-2018-1061', 'CVE-2015-2059', 'CVE-2015-0247', 'CVE-2015-8984', 'CVE-2020-14422', 'CVE-2015-4041', 'CVE-2017-1000158', 'CVE-2019-15903', 'CVE-2020-6829', '463a9a24225c26f7a5bf3f38908e5cb3', 'CVE-2019-9740', 'VULNDB-101385', 'CVE-2018-1060', 'CVE-2019-12900', 'CVE-2014-3591', 'CVE-2018-14647', 'CCE-80523-4', 'CVE-2018-20852', 'c2e44319ae5b3b040044d8ae116d1c2f', 'CVE-2019-16056', 'CCE-80171-2', 'CVE-2015-8985', 'CCE-80525-9', 'CVE-2020-12400', 'VULNDB-101497', 'CVE-2019-11727', 'VULNDB-101383', 'VULNDB-181184', 'CVE-2019-19126', 'CVE-2014-3638', 'CVE-2019-9947', '698044205a9c4a6d48b7937e66a6bf4f', 'CVE-2016-5699', 'CVE-2019-20386', 'VULNDB-222554', 'addbb93c22e9b0988b8b40392a4538cb', 'CVE-2014-5270', 'CVE-2009-5155', 'CVE-2019-9674', 'CCE-80528-3', 'CCE-80527-5', 'CVE-2018-10754', 'CVE-2014-3639'} Whitelist Set Length: 131 Vuln Set: {'CVE-2019-12900', 'CVE-2017-18207', 'CVE-2019-5188', 'CVE-2014-4616', 'VULNDB-108369', 'CVE-2020-12243', 'VULNDB-200148', 'CVE-2014-3591', 'CVE-2020-12413', 'CVE-2018-14647', 'VULNDB-101385', 'CVE-2018-20852', 'CCE-80438-5', 'VULNDB-217762', 'CVE-2014-4617', 'CVE-2014-1912', 'CVE-2019-16056', 'VULNDB-137890', 'CVE-2020-8177', 'CVE-2019-17023', 'CVE-2016-0772', 'CVE-2020-12400', 'CVE-2019-18348', 'CVE-2020-7595', 'CVE-2019-17006', 'CCE-27157-7', 'CVE-2013-7040', 'CVE-2013-1753', 'VULNDB-101497', 'CVE-2019-11727', 'CVE-2020-12399', 'CVE-2016-1000110', 'CVE-2019-19126', 'CCE-80134-0', 'CVE-2016-5636', 'CVE-2019-19956', 'VULNDB-101383', 'VULNDB-181184', 'CVE-2014-4043', 'CVE-2019-11756', 'CVE-2019-9947', 'CVE-2019-20388', 'CVE-2013-7440', 'CCE-27209-6', 'CVE-2017-17522', 'CVE-2020-26116', 'CVE-2019-20907', 'CVE-2019-16935', 'CVE-2019-17498', 'CVE-2019-18276', 'CVE-2014-9365', 'CVE-2015-5652', 'CVE-2019-5010', 'CVE-2019-17450', 'CVE-2016-5699', 'CVE-2020-12402', 'CVE-2019-20386', 'CVE-2019-9948', 'VULNDB-222554', 'CVE-2020-12403', 'CVE-2018-1061', 'CVE-2015-2059', 'CVE-2015-0247', 'CVE-2014-5270', 'CVE-2020-14422', 'CVE-2020-12401', 'CVE-2019-15903', 'CVE-2017-1000158', 'CVE-2019-3842', 'CVE-2018-1000030', 'CVE-2019-9674', 'CVE-2020-6829', 'CVE-2014-7185', 'CVE-2019-9740', 'CVE-2019-18197', 'CVE-2018-1060'} Vuln Set Length: 76 NON-WHITELISTED VULNERABILITIES FOUND Vuln Set Delta: {'CVE-2020-26116'} Vuln Set Delta Length: 1 Scans are not passing 100%. Vuln Set Delta Length: 1 section_end:1601420634:step_script Job succeeded