-
Notifications
You must be signed in to change notification settings - Fork 297
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix weak hash false positive in oracle.security.o5logon.O5Logon #8608
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
smola
approved these changes
Mar 24, 2025
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 65 metrics, 6 unstable metrics. Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.046 s) : 0, 1046427
Total [baseline] (8.698 s) : 0, 8698078
Agent [candidate] (1.05 s) : 0, 1050396
Total [candidate] (8.662 s) : 0, 8661992
section iast
Agent [baseline] (1.177 s) : 0, 1176529
Total [baseline] (9.222 s) : 0, 9221947
Agent [candidate] (1.176 s) : 0, 1176106
Total [candidate] (9.235 s) : 0, 9235197
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.186 s) : 0, 1185965
Total [baseline] (9.241 s) : 0, 9241174
Agent [candidate] (1.186 s) : 0, 1186213
Total [candidate] (9.253 s) : 0, 9253018
section iast_TELEMETRY_OFF
Agent [baseline] (1.178 s) : 0, 1178467
Total [baseline] (9.271 s) : 0, 9270706
Agent [candidate] (1.179 s) : 0, 1179020
Total [candidate] (9.24 s) : 0, 9239679
gantt
title insecure-bank - break down per module: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (718.017 ms) : 0, 718017
BytebuddyAgent [candidate] (719.31 ms) : 0, 719310
GlobalTracer [baseline] (239.959 ms) : 0, 239959
GlobalTracer [candidate] (240.001 ms) : 0, 240001
AppSec [baseline] (54.611 ms) : 0, 54611
AppSec [candidate] (55.028 ms) : 0, 55028
Debugger [baseline] (4.398 ms) : 0, 4398
Debugger [candidate] (4.432 ms) : 0, 4432
Remote Config [baseline] (701.713 µs) : 0, 702
Remote Config [candidate] (721.376 µs) : 0, 721
Telemetry [baseline] (12.733 ms) : 0, 12733
Telemetry [candidate] (14.889 ms) : 0, 14889
section iast
BytebuddyAgent [baseline] (838.522 ms) : 0, 838522
BytebuddyAgent [candidate] (837.885 ms) : 0, 837885
GlobalTracer [baseline] (229.916 ms) : 0, 229916
GlobalTracer [candidate] (229.985 ms) : 0, 229985
IAST [baseline] (22.696 ms) : 0, 22696
IAST [candidate] (22.835 ms) : 0, 22835
AppSec [baseline] (55.991 ms) : 0, 55991
AppSec [candidate] (55.802 ms) : 0, 55802
Debugger [baseline] (4.141 ms) : 0, 4141
Debugger [candidate] (4.175 ms) : 0, 4175
Remote Config [baseline] (595.984 µs) : 0, 596
Remote Config [candidate] (598.238 µs) : 0, 598
Telemetry [baseline] (8.736 ms) : 0, 8736
Telemetry [candidate] (8.746 ms) : 0, 8746
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (844.816 ms) : 0, 844816
BytebuddyAgent [candidate] (845.497 ms) : 0, 845497
GlobalTracer [baseline] (231.493 ms) : 0, 231493
GlobalTracer [candidate] (231.568 ms) : 0, 231568
IAST [baseline] (23.09 ms) : 0, 23090
IAST [candidate] (23.12 ms) : 0, 23120
AppSec [baseline] (56.741 ms) : 0, 56741
AppSec [candidate] (56.284 ms) : 0, 56284
Debugger [baseline] (4.214 ms) : 0, 4214
Debugger [candidate] (4.18 ms) : 0, 4180
Remote Config [baseline] (615.35 µs) : 0, 615
Remote Config [candidate] (602.351 µs) : 0, 602
Telemetry [baseline] (8.883 ms) : 0, 8883
Telemetry [candidate] (8.878 ms) : 0, 8878
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (840.463 ms) : 0, 840463
BytebuddyAgent [candidate] (839.645 ms) : 0, 839645
GlobalTracer [baseline] (230.224 ms) : 0, 230224
GlobalTracer [candidate] (231.5 ms) : 0, 231500
IAST [baseline] (22.398 ms) : 0, 22398
IAST [candidate] (23.272 ms) : 0, 23272
AppSec [baseline] (55.971 ms) : 0, 55971
AppSec [candidate] (55.272 ms) : 0, 55272
Debugger [baseline] (4.141 ms) : 0, 4141
Debugger [candidate] (4.141 ms) : 0, 4141
Remote Config [baseline] (605.883 µs) : 0, 606
Remote Config [candidate] (590.636 µs) : 0, 591
Telemetry [baseline] (8.578 ms) : 0, 8578
Telemetry [candidate] (8.588 ms) : 0, 8588
Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.048 s) : 0, 1048214
Total [baseline] (10.463 s) : 0, 10462912
Agent [candidate] (1.047 s) : 0, 1046732
Total [candidate] (10.478 s) : 0, 10477706
section appsec
Agent [baseline] (1.188 s) : 0, 1188123
Total [baseline] (10.796 s) : 0, 10795792
Agent [candidate] (1.196 s) : 0, 1195689
Total [candidate] (10.793 s) : 0, 10793059
section iast
Agent [baseline] (1.177 s) : 0, 1176611
Total [baseline] (11.012 s) : 0, 11012027
Agent [candidate] (1.189 s) : 0, 1189390
Total [candidate] (11.032 s) : 0, 11032147
section profiling
Agent [baseline] (1.282 s) : 0, 1282410
Total [baseline] (10.928 s) : 0, 10927500
Agent [candidate] (1.27 s) : 0, 1270343
Total [candidate] (10.816 s) : 0, 10815893
gantt
title petclinic - break down per module: candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (718.222 ms) : 0, 718222
BytebuddyAgent [candidate] (718.238 ms) : 0, 718238
GlobalTracer [baseline] (239.693 ms) : 0, 239693
GlobalTracer [candidate] (239.623 ms) : 0, 239623
AppSec [baseline] (54.863 ms) : 0, 54863
AppSec [candidate] (54.689 ms) : 0, 54689
Debugger [baseline] (5.859 ms) : 0, 5859
Debugger [candidate] (5.155 ms) : 0, 5155
Remote Config [baseline] (712.222 µs) : 0, 712
Remote Config [candidate] (708.45 µs) : 0, 708
Telemetry [baseline] (12.841 ms) : 0, 12841
Telemetry [candidate] (12.314 ms) : 0, 12314
section appsec
BytebuddyAgent [baseline] (736.019 ms) : 0, 736019
BytebuddyAgent [candidate] (741.219 ms) : 0, 741219
GlobalTracer [baseline] (236.094 ms) : 0, 236094
GlobalTracer [candidate] (237.728 ms) : 0, 237728
IAST [baseline] (21.537 ms) : 0, 21537
IAST [candidate] (21.459 ms) : 0, 21459
AppSec [baseline] (175.725 ms) : 0, 175725
AppSec [candidate] (176.279 ms) : 0, 176279
Debugger [baseline] (4.298 ms) : 0, 4298
Debugger [candidate] (4.328 ms) : 0, 4328
Remote Config [baseline] (652.95 µs) : 0, 653
Remote Config [candidate] (651.781 µs) : 0, 652
Telemetry [baseline] (8.532 ms) : 0, 8532
Telemetry [candidate] (8.649 ms) : 0, 8649
section iast
BytebuddyAgent [baseline] (838.133 ms) : 0, 838133
BytebuddyAgent [candidate] (846.985 ms) : 0, 846985
GlobalTracer [baseline] (230.172 ms) : 0, 230172
GlobalTracer [candidate] (232.853 ms) : 0, 232853
IAST [baseline] (22.764 ms) : 0, 22764
IAST [candidate] (23.418 ms) : 0, 23418
AppSec [baseline] (56.182 ms) : 0, 56182
AppSec [candidate] (56.372 ms) : 0, 56372
Debugger [baseline] (4.123 ms) : 0, 4123
Debugger [candidate] (4.179 ms) : 0, 4179
Remote Config [baseline] (588.482 µs) : 0, 588
Remote Config [candidate] (607.725 µs) : 0, 608
Telemetry [baseline] (8.684 ms) : 0, 8684
Telemetry [candidate] (8.797 ms) : 0, 8797
section profiling
BytebuddyAgent [baseline] (714.074 ms) : 0, 714074
BytebuddyAgent [candidate] (708.957 ms) : 0, 708957
GlobalTracer [baseline] (353.625 ms) : 0, 353625
GlobalTracer [candidate] (349.97 ms) : 0, 349970
AppSec [baseline] (54.898 ms) : 0, 54898
AppSec [candidate] (53.451 ms) : 0, 53451
Debugger [baseline] (4.368 ms) : 0, 4368
Debugger [candidate] (4.254 ms) : 0, 4254
Remote Config [baseline] (713.936 µs) : 0, 714
Remote Config [candidate] (703.543 µs) : 0, 704
Telemetry [baseline] (9.172 ms) : 0, 9172
Telemetry [candidate] (8.926 ms) : 0, 8926
ProfilingAgent [baseline] (103.473 ms) : 0, 103473
ProfilingAgent [candidate] (102.503 ms) : 0, 102503
Profiling [baseline] (103.631 ms) : 0, 103631
Profiling [candidate] (102.53 ms) : 0, 102530
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 13 metrics, 17 unstable metrics. Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (387.414 µs) : 367, 408
. : milestone, 387,
iast (523.618 µs) : 502, 545
. : milestone, 524,
iast_FULL (737.228 µs) : 715, 759
. : milestone, 737,
iast_GLOBAL (569.741 µs) : 548, 592
. : milestone, 570,
iast_HARDCODED_SECRET_DISABLED (513.573 µs) : 492, 535
. : milestone, 514,
iast_INACTIVE (466.618 µs) : 445, 488
. : milestone, 467,
iast_TELEMETRY_OFF (508.999 µs) : 487, 531
. : milestone, 509,
tracing (461.4 µs) : 440, 483
. : milestone, 461,
section candidate
no_agent (394.125 µs) : 374, 414
. : milestone, 394,
iast (521.509 µs) : 500, 543
. : milestone, 522,
iast_FULL (732.422 µs) : 710, 754
. : milestone, 732,
iast_GLOBAL (564.385 µs) : 542, 587
. : milestone, 564,
iast_HARDCODED_SECRET_DISABLED (519.527 µs) : 498, 541
. : milestone, 520,
iast_INACTIVE (471.714 µs) : 449, 494
. : milestone, 472,
iast_TELEMETRY_OFF (504.235 µs) : 482, 526
. : milestone, 504,
tracing (462.592 µs) : 442, 483
. : milestone, 463,
Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (1.373 ms) : 1352, 1393
. : milestone, 1373,
appsec (1.734 ms) : 1710, 1758
. : milestone, 1734,
appsec_no_iast (1.739 ms) : 1715, 1762
. : milestone, 1739,
code_origins (1.688 ms) : 1661, 1716
. : milestone, 1688,
iast (1.518 ms) : 1493, 1542
. : milestone, 1518,
profiling (1.577 ms) : 1552, 1602
. : milestone, 1577,
tracing (1.496 ms) : 1471, 1521
. : milestone, 1496,
section candidate
no_agent (1.37 ms) : 1351, 1390
. : milestone, 1370,
appsec (1.747 ms) : 1723, 1770
. : milestone, 1747,
appsec_no_iast (1.742 ms) : 1719, 1765
. : milestone, 1742,
code_origins (1.67 ms) : 1642, 1697
. : milestone, 1670,
iast (1.516 ms) : 1491, 1541
. : milestone, 1516,
profiling (1.529 ms) : 1504, 1555
. : milestone, 1529,
tracing (1.511 ms) : 1486, 1535
. : milestone, 1511,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 1 unstable metrics. Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (1.475 ms) : 1463, 1486
. : milestone, 1475,
appsec (2.331 ms) : 2288, 2375
. : milestone, 2331,
iast (2.12 ms) : 2065, 2175
. : milestone, 2120,
iast_GLOBAL (2.172 ms) : 2116, 2228
. : milestone, 2172,
profiling (2.439 ms) : 2258, 2621
. : milestone, 2439,
tracing (1.956 ms) : 1913, 1999
. : milestone, 1956,
section candidate
no_agent (1.473 ms) : 1461, 1484
. : milestone, 1473,
appsec (2.351 ms) : 2307, 2395
. : milestone, 2351,
iast (2.123 ms) : 2068, 2179
. : milestone, 2123,
iast_GLOBAL (2.163 ms) : 2107, 2219
. : milestone, 2163,
profiling (1.968 ms) : 1924, 2012
. : milestone, 1968,
tracing (1.952 ms) : 1910, 1995
. : milestone, 1952,
Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.48.0-SNAPSHOT~ab7b08c058, baseline=1.48.0-SNAPSHOT~51813bdfcb
dateFormat X
axisFormat %s
section baseline
no_agent (14.835 s) : 14835000, 14835000
. : milestone, 14835000,
appsec (15.096 s) : 15096000, 15096000
. : milestone, 15096000,
iast (19.106 s) : 19106000, 19106000
. : milestone, 19106000,
iast_GLOBAL (18.107 s) : 18107000, 18107000
. : milestone, 18107000,
profiling (15.145 s) : 15145000, 15145000
. : milestone, 15145000,
tracing (15.086 s) : 15086000, 15086000
. : milestone, 15086000,
section candidate
no_agent (15.597 s) : 15597000, 15597000
. : milestone, 15597000,
appsec (15.379 s) : 15379000, 15379000
. : milestone, 15379000,
iast (19.126 s) : 19126000, 19126000
. : milestone, 19126000,
iast_GLOBAL (17.671 s) : 17671000, 17671000
. : milestone, 17671000,
profiling (15.038 s) : 15038000, 15038000
. : milestone, 15038000,
tracing (15.136 s) : 15136000, 15136000
. : milestone, 15136000,
|
manuel-alvarez-alvarez
approved these changes
Mar 24, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Does This Do
Exclude oracle.security.o5logon.O5Logon in IAST
Motivation
Additional Notes
Contributor Checklist
type:
and (comp:
orinst:
) labels in addition to any usefull labelsclose
,fix
or any linking keywords when referencing an issue.Use
solves
instead, and assign the PR milestone to the issueJira ticket: APPSEC-57044