Skip to content

CHEF-28294: Fix CVE-2025-61780 - Update rack gem to >= 3.1.18 #219

CHEF-28294: Fix CVE-2025-61780 - Update rack gem to >= 3.1.18

CHEF-28294: Fix CVE-2025-61780 - Update rack gem to >= 3.1.18 #219

Triggered via pull request December 9, 2025 09:25
@jashaikjashaik
synchronize #4129
CHEF-28294
Status Success
Total duration 3m 30s
Artifacts 7
call-ci-main-pr-check-pipeline  /  Checkout repository
9s
call-ci-main-pr-check-pipeline / Checkout repository
Echo stub version
2s
Echo stub version
call-ci-main-pr-check-pipeline  /  Pre-compilation checks
3s
call-ci-main-pr-check-pipeline / Pre-compilation checks
call-ci-main-pr-check-pipeline  /  Generate a simple slug based on repo and date for use in any output artifacts
4s
call-ci-main-pr-check-pipeline / Generate a simple slug based on repo and date for use in any output artifacts
call-ci-main-pr-check-pipeline  /  Build and compilation
4s
call-ci-main-pr-check-pipeline / Build and compilation
call-ci-main-pr-check-pipeline  /  ...  /  Complexity and SLOC generation
22s
call-ci-main-pr-check-pipeline / Source code complexity checks / Complexity and SLOC generation
call-ci-main-pr-check-pipeline  /  Language-specific pre-compilation steps and linting
0s
call-ci-main-pr-check-pipeline / Language-specific pre-compilation steps and linting
call-ci-main-pr-check-pipeline  /  Language-agnostic pre-compilation steps
0s
call-ci-main-pr-check-pipeline / Language-agnostic pre-compilation steps
call-ci-main-pr-check-pipeline  /  ...  /  Trufflehog
17s
call-ci-main-pr-check-pipeline / Trufflehog scan / Trufflehog
call-ci-main-pr-check-pipeline  /  ...  /  Trivy dependency vulnerability scan
31s
call-ci-main-pr-check-pipeline / Trivy scan / Trivy dependency vulnerability scan
call-ci-main-pr-check-pipeline  /  BlackDuck-Polaris-SAST
30s
call-ci-main-pr-check-pipeline / BlackDuck-Polaris-SAST
call-ci-main-pr-check-pipeline  /  Creating packaged binaries
0s
call-ci-main-pr-check-pipeline / Creating packaged binaries
call-ci-main-pr-check-pipeline  /  ...  /  Export SBOM from GitHub Dependency Graph API
1m 43s
call-ci-main-pr-check-pipeline / Generating SBOM / Export SBOM from GitHub Dependency Graph API
call-ci-main-pr-check-pipeline  /  ...  /  Generate SBOM using Blackduck Tool (BLUE)
27s
call-ci-main-pr-check-pipeline / Generating SBOM / Generate SBOM using Blackduck Tool (BLUE)
call-ci-main-pr-check-pipeline  /  ...  /  Generate MSFT SBOM
0s
call-ci-main-pr-check-pipeline / Generating SBOM / Generate MSFT SBOM
call-ci-main-pr-check-pipeline  /  ...  /  license_scout
call-ci-main-pr-check-pipeline / Generating SBOM / license_scout
call-ci-main-pr-check-pipeline  /  Detect SBOM version for application
0s
call-ci-main-pr-check-pipeline / Detect SBOM version for application
call-ci-main-pr-check-pipeline  /  ...  /  SonarQube
3m 3s
call-ci-main-pr-check-pipeline / PUBLIC Sonar SAST scan / SonarQube
call-ci-main-pr-check-pipeline  /  PRIVATE Sonar scan (inline)
0s
call-ci-main-pr-check-pipeline / PRIVATE Sonar scan (inline)
call-ci-main-pr-check-pipeline  /  ...  /  Checkout code
call-ci-main-pr-check-pipeline / INTERNAL Sonar scan / Checkout code
call-ci-main-pr-check-pipeline  /  ...  /  SonarQube
call-ci-main-pr-check-pipeline / INTERNAL Sonar scan / SonarQube
call-ci-main-pr-check-pipeline  /  ...  /  build
call-ci-main-pr-check-pipeline / INTERNAL Sonar scan / build
call-ci-main-pr-check-pipeline  /  ...  /  unit-tests
call-ci-main-pr-check-pipeline / INTERNAL Sonar scan / unit-tests
Matrix: call-ci-main-pr-check-pipeline / Unit tests
call-ci-main-pr-check-pipeline  /  Creating Habitat packages
call-ci-main-pr-check-pipeline / Creating Habitat packages
call-ci-main-pr-check-pipeline  /  ...  /  irfan
call-ci-main-pr-check-pipeline / Reporting to quality dashboard / irfan
call-ci-main-pr-check-pipeline  /  Publishing packages
call-ci-main-pr-check-pipeline / Publishing packages
Fit to window
Zoom out
Zoom in

Annotations

1 error and 2 warnings
call-ci-main-pr-check-pipeline / BlackDuck-Polaris-SAST
Workflow failed! Exit Code: 2 Error from adapter end
call-ci-main-pr-check-pipeline / PUBLIC Sonar SAST scan / SonarQube
Removing 57.151.137.181 from the Storage Account Firewall, Please Wait...
call-ci-main-pr-check-pipeline / PUBLIC Sonar SAST scan / SonarQube
adding 57.151.137.181 To Storage Account Firewall, Please Wait...

Artifacts

Produced during runtime
Name Size Digest
chef-chef-server-20251209092537-GitHub-sbom.json Expired
37.4 KB
sha256:0737bf49dd8b5eae59d6e613e0524d728ad2fd6966aae59e0c9334ed2a6ada56
chef-chef-server-4129-merge-15.10.63--20251209092531-Trivy.json Expired
2.92 KB
sha256:5e63113173fb28d232b37d22617837a4e6dadbb388f12d7e0c5464abc9bdc13d
chef-chef-server-4129-merge-15.10.63--20251209092531-Trivy.txt Expired
1.81 KB
sha256:08f9153957b1803edcf76d00c14a7b82d0b4e20d691d3b82d5686cda6d73d1ec
chef-chef-server-4129-merge-15.10.63-20251209092537-GitHub-sbom.csv Expired
15 KB
sha256:83c5bb48dd90fa3ceb37c924bf44a67af942c74c33b3a6fd8f4d1091ee13dcfe
chef-chef-server-4129-merge-20251209092543-scc-complexity.html Expired
41.2 KB
sha256:88944c4be24875d5a2fa7a962813d2b6ea3bc3fb1ad98eab8f6e77b6c60fc81d
chef-chef-server-4129-merge-20251209092543-scc-complexity.json Expired
54.1 KB
sha256:63aae402ff41e01a599d176ae62ba80836e08d5c0ec4a4eef1b51cdb166edb59
chef-chef-server-4129-merge-20251209092543-scc-complexity.txt Expired
1.12 KB
sha256:43af936733d01248626072c1f224eaa57a2f482148490a7cadd9cc5e99430555