Skip to content

Secret Scanner publishes scan being ran as a secret finding to xray #1295

@CyberT17

Description

@CyberT17

Describe the bug

I am running Frogbot CLI against bitbucket server repos. There is a bug where frogbot is pushing scans being ran as a secret finding to xray. The Description of the finding is The scanner REQ.SECRET.GENERIC.TEXT has ran with an empty file path.

Running the latest version (2.32.2) of frogbot at the time of this issue creation on a self-hosted artifactory instance.

Current behavior

There are no errors in the logs. The scan completes successfully.
Image

Reproduction steps

No response

Expected behavior

No response

JFrog Frogbot version

2.32.2

Package manager info

Occurs on a bunch of package types, Gradle, Ant, Maven, Html/css/js

Git provider

Bitbucket Server

JFrog Frogbot configuration yaml file

- params:
    git:
      repoName: my-repo-name
      branches:
        - master

Operating system type and version

ubuntu 24.04

JFrog Xray version

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions