UNCLASSIFIED

Update sonarqube:8.9-community Docker digest to 0fc6c71

14 jobs for renovate/sonarqube-8.9-community in 12 minutes and 15 seconds (queued for 7 seconds)
Status Job ID Name Coverage
  .Pre
passed #4120488
load-scripts

00:00:11

 
  Preflight
passed #4120490
folder-structure

00:00:09

passed #4120491
hardening-manifest

00:00:18

passed #4120489
trufflehog

00:00:10

 
  Lint
passed #4120492
wl-compare-lint

00:00:15

 
  Import Artifacts
passed #4120493
import-artifacts

00:01:00

 
  Scan Artifacts
passed #4120494
clamav-scan

00:02:10

 
  Build
passed #4120495
build

00:02:33

 
  Scanning
passed #4120496
anchore-scan

00:04:28

passed #4120497
ironbank-dsop-privileged
openscap-compliance

00:01:16

passed #4120498
twistlock-scan

00:01:31

 
  Csv Output
passed #4120499
csv-output

00:00:32

 
  Check Cves
failed #4120500
allowed to fail
check-cves

00:00:27

 
  Documentation
passed #4120501
create-tar

00:00:59

 
Name Stage Failure
failed
check-cves Check Cves
ERROR: The following vulnerabilities are not whitelisted:
ERROR: scan_source cve_id package package_path
ERROR: anchore_cve VULNDB-256815 commons-compress-1.20 /opt/sonarqube/lib/extensions/sonar-javascript-plugin-7.4.4.15624.jar:commons-compress
ERROR: anchore_cve VULNDB-257084 commons-compress-1.20 /opt/sonarqube/lib/extensions/sonar-javascript-plugin-7.4.4.15624.jar:commons-compress
ERROR: anchore_cve GHSA-5mg8-w23w-74h3 guava-28.2-jre /opt/sonarqube/lib/scanner/sonar-scanner-engine-shaded-8.9.1.44547-all.jar:guava
ERROR: anchore_cve GHSA-5mg8-w23w-74h3 guava-28.2-jre /opt/sonarqube/lib/sonar-application-8.9.1.44547.jar:guava
ERROR: anchore_cve CVE-2020-13697 nanohttpd-2.3.1 /opt/sonarqube/lib/sonar-application-8.9.1.44547.jar:nanohttpd
Cleaning up file based variables
ERROR: Job failed: command terminated with exit code 1