Newbie here. My angular project got 0 violation - Sonatype Lifecycle & Repository Firewall - Sonatype Community
Newbie here. My angular project got 0 violation
post by joehowistronits on Nov 12, 2023
It’s quite surprising that I received zero violations.
While having zero violations is a positive outcome, it hasn’t convinced my boss :(.
There is no ‘package-lock.json’ in my repository.
What did I miss in my CI process?
The following are my ‘ng build’ and ‘sca’ stages and scan output.
NgBuild:
only:
- master
image: xxx.com/base_image/ng-cli-karma
stage: NgBuild
script:
- npm cache clean --force
- npm install --save --save-exact
- ls -ltra
- ng build --configuration development
tags:
- k8s-runners
artifacts:
paths:
- ./package-lock.json
- ./package.json
- ./dist
when: always
expire_in: 1 days
sca:
only:
- master
image: xxxx.com/base_image/gitlab-nexus-iq-pipeline:latest
stage: sca
tags:
- k8s-runners
script:
- /sonatype/evaluate -i $CI_PROJECT_TITLE ./
allow_failure: true
artifacts:
paths:
- ./package-lock.json
- ./dist
when: always
expire_in: 1 days
$ /sonatype/evaluate -i $CI_PROJECT_TITLE ./
Commencing Nexus IQ policy evaluation...
[INFO] Validating IQ Server version https://sca.xxx.com...
...Nexus IQ policy evaluation complete
Uploading artifacts for successful job
Uploading artifacts...
./package-lock.json: found 1 matching files and directories
./dist: found 1652 matching files and directories
post by joehowistronits on Nov 12, 2023
Since the package-lock.json is not in the source control, running ‘npm install’ should install the latest versions of the packages.
However, I have a gut feeling that the SCA server doesn’t have data on the latest versions for those packages.
post by mpiggott on Nov 14, 2023
Hi, I believe you’d want to post this in the Sonatype Lifecycle & Repository Firewall section of the forums, I’m afraid I don’t have the ability to move the post for you.
post by mprescott on Nov 14, 2023
I’ve moved this post to the Lifecycle/Firewall section.
post by joehowistronits on Nov 16, 2023
Thank you guys.
Just update some progress.
I use “cache” instead of the “atrfact” to retain the node_modules/.
That made some slightly difference.
The major reason should be our project always install latest version.
But I am not sure the reason is same as following article.