Running with gitlab-runner 13.12.0 (7a6612da)  on dsop-shared-gitlab-runner-5fcd8977b8-m6qmr JrExJ6yx  feature flags: FF_USE_LEGACY_KUBERNETES_EXECUTION_STRATEGY:false section_start:1631023195:resolve_secrets Resolving secrets section_end:1631023195:resolve_secrets section_start:1631023195:prepare_executor Preparing the "kubernetes" executor Using Kubernetes namespace: gitlab-runner-ironbank-dsop Using Kubernetes executor with image registry1.dso.mil/ironbank/ironbank-pipelines/pipeline-runner:0.3 ... Using attach strategy to execute scripts... section_end:1631023195:prepare_executor section_start:1631023195:prepare_script Preparing environment Waiting for pod gitlab-runner-ironbank-dsop/runner-jrexj6yx-project-1385-concurrent-0ksss7 to be running, status is Pending ContainersNotInitialized: "containers with incomplete status: [init-logs istio-init]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" Waiting for pod gitlab-runner-ironbank-dsop/runner-jrexj6yx-project-1385-concurrent-0ksss7 to be running, status is Pending ContainersNotInitialized: "containers with incomplete status: [init-logs istio-init]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" Waiting for pod gitlab-runner-ironbank-dsop/runner-jrexj6yx-project-1385-concurrent-0ksss7 to be running, status is Pending ContainersNotInitialized: "containers with incomplete status: [istio-init]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" Waiting for pod gitlab-runner-ironbank-dsop/runner-jrexj6yx-project-1385-concurrent-0ksss7 to be running, status is Pending ContainersNotReady: "containers with unready status: [build helper istio-proxy]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" Waiting for pod gitlab-runner-ironbank-dsop/runner-jrexj6yx-project-1385-concurrent-0ksss7 to be running, status is Pending ContainersNotReady: "containers with unready status: [build helper istio-proxy]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" Waiting for pod gitlab-runner-ironbank-dsop/runner-jrexj6yx-project-1385-concurrent-0ksss7 to be running, status is Pending ContainersNotReady: "containers with unready status: [build helper istio-proxy]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" Waiting for pod gitlab-runner-ironbank-dsop/runner-jrexj6yx-project-1385-concurrent-0ksss7 to be running, status is Pending ContainersNotReady: "containers with unready status: [build helper istio-proxy]" ContainersNotReady: "containers with unready status: [build helper istio-proxy]" Running on runner-jrexj6yx-project-1385-concurrent-0ksss7 via dsop-shared-gitlab-runner-5fcd8977b8-m6qmr... section_end:1631023216:prepare_script section_start:1631023216:get_sources Getting source from Git repository $ until [ $(curl --fail --silent --output /dev/stderr --write-out "%{http_code}" localhost:15020/healthz/ready) -eq 200 ]; do echo Waiting for Sidecar; sleep 3 ; done ; echo Sidecar available; Waiting for Sidecar Sidecar available Fetching changes with git depth set to 50... Initialized empty Git repository in /builds/JrExJ6yx/0/dsop/redhat/ubi/ubi7-minimal/.git/ Created fresh repository. Checking out 5e7b449a as master... Skipping Git submodules setup section_end:1631023220:get_sources section_start:1631023220:download_artifacts Downloading artifacts Downloading artifacts for anchore-scan (6300459)... Downloading artifacts from coordinator... ok  id=6300459 responseStatus=200 OK token=bqxXzXF9 WARNING: ci-artifacts/scan-results/anchore/: lchown ci-artifacts/scan-results/anchore/: operation not permitted (suppressing repeats) Downloading artifacts for hardening-manifest (6300453)... Downloading artifacts from coordinator... ok  id=6300453 responseStatus=200 OK token=yT1FCmqQ WARNING: ci-artifacts/preflight/: lchown ci-artifacts/preflight/: operation not permitted (suppressing repeats) Downloading artifacts for load-scripts (6300450)... Downloading artifacts from coordinator... ok  id=6300450 responseStatus=200 OK token=xiUnazhd WARNING: ci-artifacts/[MASKED]/: lchown ci-artifacts/[MASKED]/: operation not permitted (suppressing repeats) Downloading artifacts for openscap-compliance (6300460)... Downloading artifacts from coordinator... ok  id=6300460 responseStatus=200 OK token=2kXXgYA3 WARNING: ci-artifacts/scan-results/openscap/: lchown ci-artifacts/scan-results/openscap/: operation not permitted (suppressing repeats) Downloading artifacts for twistlock-scan (6300461)... Downloading artifacts from coordinator... ok  id=6300461 responseStatus=200 OK token=mi9Tzsja WARNING: ci-artifacts/scan-results/twistlock/: lchown ci-artifacts/scan-results/twistlock/: operation not permitted (suppressing repeats) Downloading artifacts for wl-compare-lint (6300454)... Downloading artifacts from coordinator... ok  id=6300454 responseStatus=200 OK token=Z_xmTixs WARNING: ci-artifacts/lint/: lchown ci-artifacts/lint/: operation not permitted (suppressing repeats) section_end:1631023222:download_artifacts section_start:1631023222:step_script Executing "step_script" stage of the job script $ pip3 install jsonschema # collapsed multi-line command Requirement already satisfied: jsonschema in /usr/local/lib/python3.9/site-packages (3.2.0) Requirement already satisfied: six>=1.11.0 in /usr/local/lib/python3.9/site-packages (from jsonschema) (1.15.0) Requirement already satisfied: pyrsistent>=0.14.0 in /usr/local/lib/python3.9/site-packages (from jsonschema) (0.17.3) Requirement already satisfied: attrs>=17.4.0 in /usr/local/lib/python3.9/site-packages (from jsonschema) (21.2.0) Requirement already satisfied: setuptools in /usr/local/lib/python3.9/site-packages (from jsonschema) (56.1.0) WARNING: Running pip as root will break packages and permissions. You should install packages reliably by using venv: https://pip.pypa.io/warnings/venv WARNING: You are using pip version 21.1.1; however, version 21.2.4 is available. You should consider upgrading via the '/usr/local/bin/python3.9 -m pip install --upgrade pip' command. INFO: Log level set to info INFO: Number of whitelisted vulnerabilities: 35 INFO: Whitelisted vulnerabilities: {Finding(scan_source='oscap_comp', cve_id='CCE-80525-9', package=None, package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-23840', package='openssl-libs-1.0.2k-21.el7_9', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80531-7', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80530-9', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36087', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-3712', package='openssl-libs-1.0.2k-21.el7_9', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80534-1', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36085', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80521-8', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80524-2', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-27209-6', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80532-5', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80438-5', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80134-0', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80535-8', package=None, package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-37750', package='krb5-libs-1.15.1-50.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80523-4', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80529-1', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36084', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36084', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80368-4', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-27285-6', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80526-7', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80533-3', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80536-6', package=None, package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36085', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80171-2', package=None, package_path=None), Finding(scan_source='anchore_comp', cve_id='41cb7cdf04850e33a11f80c42bf660b3', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80522-6', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80527-5', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36086', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36086', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36087', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-23841', package='openssl-libs-1.0.2k-21.el7_9', package_path=None), Finding(scan_source='anchore_comp', cve_id='cbff271f45d32e78dcc1979dbca9c14d', package=None, package_path=None)} INFO: Vulnerabilities found in scanning stage: 35 INFO: {Finding(scan_source='oscap_comp', cve_id='CCE-80525-9', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36087', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80531-7', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80530-9', package=None, package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-23840', package='openssl-libs-1.0.2k-21.el7_9', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-3712', package='openssl-libs-1.0.2k-21.el7_9', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80534-1', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36085', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80521-8', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80524-2', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-27209-6', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80532-5', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80438-5', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80134-0', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80535-8', package=None, package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-37750', package='krb5-libs-1.15.1-50.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80523-4', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80529-1', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36084', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36084', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80368-4', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80533-3', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80526-7', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80536-6', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-27285-6', package=None, package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36085', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80171-2', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80527-5', package=None, package_path=None), Finding(scan_source='oscap_comp', cve_id='CCE-80522-6', package=None, package_path=None), Finding(scan_source='twistlock_cve', cve_id='CVE-2021-36086', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_comp', cve_id='41cb7cdf04850e33a11f80c42bf660b3', package=None, package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36086', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-36087', package='libsepol-2.5-10.el7', package_path=None), Finding(scan_source='anchore_cve', cve_id='CVE-2021-23841', package='openssl-libs-1.0.2k-21.el7_9', package_path=None), Finding(scan_source='anchore_comp', cve_id='cbff271f45d32e78dcc1979dbca9c14d', package=None, package_path=None)} INFO: ALL VULNERABILITIES WHITELISTED INFO: Scans are passing 100% section_end:1631023230:step_script section_start:1631023230:cleanup_file_variables Cleaning up file based variables section_end:1631023230:cleanup_file_variables Job succeeded