snyk-container-test-delta ○ canceled

Duration: 1m 20s
Queued: 1s
📁 Stage: test
🖥 Runner: linux-aws-1
Average Duration
3m 15s
This job: 1m 20s
Failure Rate
5.9%
last 30 days

Job Execution Phases

💡 Tip: Click on any phase bar to jump to that section in the log below

Full Job Log

110 lines
Match - of 0
1 14:27:36 Running with gitlab-runner 18.5.0 (bda84871)
2 14:27:36 on gitlab-runner-linux-1-86d76d468c-6ntxl wRxjPbsJX, system ID: r_2To3NBNBh3sO
3 14:27:36 feature flags: FF_USE_FASTZIP:true, FF_USE_NEW_BASH_EVAL_STRATEGY:true, FF_SCRIPT_SECTIONS:true, FF_USE_ADVANCED_POD_SPEC_CONFIGURATION:true, FF_PRINT_POD_EVENTS:true, FF_USE_DUMB_INIT_WITH_KUBERNETES_EXECUTOR:true, FF_LOG_IMAGES_CONFIGURED_FOR_JOB:true, FF_CLEAN_UP_FAILED_CACHE_EXTRACT:true, FF_TIMESTAMPS:true, FF_GIT_URLS_WITHOUT_TOKENS:true
4 14:27:36 Resolving secrets
5 14:27:36 section_start:1765290456:prepare_executor
6 14:27:36 +Preparing the "kubernetes" executor
7 14:27:36 Using Kubernetes namespace: gitlab-runner
8 14:27:36 Using Kubernetes executor with image registry.scandit.com/dockerfiles/snyk:ubuntu@sha256:b25007848b15bc7878e7301e1bb55c3df623f778624b9dba2a481c7871c6db6c ...
9 14:27:36 Using attach strategy to execute scripts...
10 14:27:36 Using effective pull policy of [Always] for container build
11 14:27:36 Using effective pull policy of [Always] for container helper
12 14:27:36 Using effective pull policy of [Always] for container init-permissions
13 14:27:36 section_end:1765290456:prepare_executor
14 14:27:36 +section_start:1765290456:prepare_script
15 14:27:36 +Preparing environment
16 14:27:36 Using FF_USE_POD_ACTIVE_DEADLINE_SECONDS, the Pod activeDeadlineSeconds will be set to the job timeout: 1h0m0s...
17 14:27:36 WARNING: Advanced Pod Spec configuration enabled, merging the provided PodSpec to the generated one. This is a beta feature and is subject to change. Feedback is collected in this issue: https://gitlab.com/gitlab-org/gitlab-runner/-/issues/29659 ...
18 14:27:37 Subscribing to Kubernetes Pod events...
19 14:27:37 Type Reason Message
20 14:27:37 Normal Scheduled Successfully assigned gitlab-runner/runner-wrxjpbsjx-project-621-concurrent-0-fgx2e9rh to ip-10-0-39-249.eu-central-1.compute.internal
21 14:27:37 Normal Pulled Container image "gitlab/gitlab-runner-helper:x86_64-v18.5.0" already present on machine
22 14:27:37 Normal Created Created container: init-permissions
23 14:27:37 Normal Started Started container init-permissions
24 14:27:38 Normal Pulling Pulling image "498954711405.dkr.ecr.eu-central-1.amazonaws.com/dockerfiles/snyk@sha256:b25007848b15bc7878e7301e1bb55c3df623f778624b9dba2a481c7871c6db6c"
25 14:27:40 Normal Pulled Successfully pulled image "498954711405.dkr.ecr.eu-central-1.amazonaws.com/dockerfiles/snyk@sha256:b25007848b15bc7878e7301e1bb55c3df623f778624b9dba2a481c7871c6db6c" in 1.95s (1.95s including waiting). Image size: 120667410 bytes.
26 14:27:40 Normal Created Created container: build
27 14:27:40 Normal Started Started container build
28 14:27:40 Normal Pulled Container image "gitlab/gitlab-runner-helper:x86_64-v18.5.0" already present on machine
29 14:27:40 Normal Created Created container: helper
30 14:27:40 Normal Started Started container helper
31 14:27:44 Running on runner-wrxjpbsjx-project-621-concurrent-0-fgx2e9rh via gitlab-runner-linux-1-86d76d468c-6ntxl...
32 14:27:44
33 14:27:44 section_end:1765290464:prepare_script
34 14:27:44 +section_start:1765290464:get_sources
35 14:27:44 +Getting source from Git repository
36 14:27:44 Gitaly correlation ID: 01KC1R5D02NY64ANS8B89FEC1T
37 14:27:44 Fetching changes with git depth set to 50...
38 14:27:44 Initialized empty Git repository in /build/internal/gitlab-templates/.git/
39 14:27:44 Created fresh repository.
40 14:27:45 Checking out 940006cc as detached HEAD (ref is refs/merge-requests/507/merge)...
41 14:27:45
42 14:27:45 Skipping Git submodules setup
43 14:27:45
44 14:27:45 section_end:1765290465:get_sources
45 14:27:45 +section_start:1765290465:step_script
46 14:27:45 +Executing "step_script" stage of the job script
47 14:27:46 section_start:1765290465:section_pre_build_script_0[hide_duration=true,collapsed=true] $ function cleanup {
48 14:27:46 rv=$?
49 14:27:46 if [ $rv -ne 0 ]; then
50 14:27:46 echo ""
51 14:27:46 echo " Failure Cause Analysis might help, please open this link:"
52 14:27:46 echo " https://failure-cause-analysis.zrh.int.scandit.io/analysis/projects/${CI_PROJECT_ID}/jobs/${CI_JOB_ID}"
53 14:27:46 echo ""
54 14:27:46 fi
55 14:27:46 echo ""
56 14:27:46 echo "Grafana Pod-View: https://grafana.scandit.com/d/k8s_views_pods/kubernetes-views-pods?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-host=${SC_K8S_NODE_NAME}&var-namespace=${SC_K8S_NAMESPACE}&var-pod=${HOSTNAME}&var-resolution=15&from=${__start_time}000&to=${EPOCHSECONDS}000"
57 14:27:46 echo "Grafana Node-View: https://grafana.scandit.com/d/k8s_views_nodes/kubernetes-views-nodes?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-node=${SC_K8S_NODE_NAME}&var-resolution=15s&from=${__start_time}000&to=${EPOCHSECONDS}000"
58 14:27:46 echo ""
59 14:27:46 exit $rv
60 14:27:46 }
61 14:27:46 trap cleanup EXIT
62 14:27:46 echo "INFO: This is the CI job pre_build_script"
63 14:27:46 echo "INFO: It's defined in the backend/infra/aws repo."
64 14:27:46 echo "INFO: These additional Scandit variables are available to you:"
65 14:27:46 echo " SC_K8S_NODE_NAME: $SC_K8S_NODE_NAME"
66 14:27:46 echo " SC_K8S_IMAGE_ID: $SC_K8S_IMAGE_ID"
67 14:27:46 echo "cpu (r/l): ${SC_K8S_REQUESTS_CPU}/${SC_K8S_LIMITS_CPU}"
68 14:27:46 if command -v numfmt >/dev/null 2>&1; then
69 14:27:46 echo "memory (r/l): $(numfmt --to=iec --suffix=B $SC_K8S_REQUESTS_MEMORY)/$(numfmt --to=iec --suffix=B $SC_K8S_LIMITS_MEMORY)"
70 14:27:46 else
71 14:27:46 echo "memory (r/l): ${SC_K8S_REQUESTS_MEMORY}/${SC_K8S_LIMITS_MEMORY}"
72 14:27:46 fi
73 14:27:46 __start_time=${EPOCHSECONDS}
74 14:27:46 echo ""
75 14:27:46 echo "Grafana Pod-View: https://grafana.scandit.com/d/k8s_views_pods/kubernetes-views-pods?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-host=${SC_K8S_NODE_NAME}&var-namespace=${SC_K8S_NAMESPACE}&var-pod=${HOSTNAME}&var-resolution=15&from=${__start_time}000&to=now"
76 14:27:46 echo "Grafana Node-View: https://grafana.scandit.com/d/k8s_views_nodes/kubernetes-views-nodes?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-node=${SC_K8S_NODE_NAME}&var-resolution=15s&from=${__start_time}000&to=now"
77 14:27:46 echo ""
78 14:27:46 echo "Setting up credentials for Gitlab Python registries"
79 14:27:46 mkdir -p ~
80 14:27:46 echo "machine gitlab.scandit.com" > ~/.netrc
81 14:27:46 echo "login gitlab-ci-token" >> ~/.netrc
82 14:27:46 echo "password ${CI_JOB_TOKEN}" >> ~/.netrc
83 14:27:46 chmod 600 ~/.netrc
84 14:27:46 if command -v git &> /dev/null && [ "$(id -u)" -ne 0 ]; then
85 14:27:46 git config --global --add safe.directory $CI_PROJECT_DIR
86 14:27:46 fi
87 14:27:46 # Sonarqube server is running on the same cluster. Use internal address
88 14:27:46 export SONAR_HOST_URL="http://sonarqube.sonarqube.svc.cluster.local:9000"
89 14:27:46 section_end:1765290465:section_pre_build_script_0
90 14:27:46 INFO: This is the CI job pre_build_script
91 14:27:46 INFO: It's defined in the backend/infra/aws repo.
92 14:27:46 INFO: These additional Scandit variables are available to you:
93 14:27:46 SC_K8S_NODE_NAME: ip-10-0-39-249.eu-central-1.compute.internal
94 14:27:46 SC_K8S_IMAGE_ID:
95 14:27:46 cpu (r/l): 1/4
96 14:27:46 memory (r/l): 1.0GB/16GB
97 14:27:46
98 14:27:46 Grafana Pod-View: https://grafana.scandit.com/d/k8s_views_pods/kubernetes-views-pods?orgId=1&refresh=1m&var-datasource=lu1rmx27z&var-host=ip-10-0-39-249.eu-central-1.compute.internal&var-namespace=gitlab-runner&var-pod=runner-wrxjpbsjx-project-621-concurrent-0-fgx2e9rh&var-resolution=15&from=1765290465000&to=now
99 14:27:46 Grafana Node-View: https://grafana.scandit.com/d/k8s_views_nodes/kubernetes-views-nodes?orgId=1&refresh=1m&var-datasource=lu1rmx27z&var-node=ip-10-0-39-249.eu-central-1.compute.internal&var-resolution=15s&from=1765290465000&to=now
100 14:27:46
101 14:27:46 Setting up credentials for Gitlab Python registries
102 14:27:46 $ echo "This job scans the given image for known vulnerabilities and outputs the result in the console."
103 14:27:46 This job scans the given image for known vulnerabilities and outputs the result in the console.
104 14:27:46 $ echo "Running 'snyk container test | snyk-delta' on image $IMAGE_URL."
105 14:27:46 Running 'snyk container test | snyk-delta' on image registry.scandit.com/internal/gitlab-templates/python:3.12-MR507.
106 14:27:46 $ snyk container test ${IMAGE_URL} --file=${DOCKERFILE_PATH} --exclude-base-image-vulns --exclude-app-vulns --policy-path=${SNYK_POLICY_PATH} --org=${SNYK_ORG} --json --json-file-output=${OUTPUT_FILE} ${SNYK_EXTRA_PARAMETERS} | snyk-delta --debug
107 14:27:46 2025-12-09T14:27:46.070Z snyk inline mode
108 14:28:11 2025-12-09T14:28:10.821Z snyk Verify input data for JSON structure
109 14:28:11 2025-12-09T14:28:11.061Z snyk Retrieving Snyk Project c1f2e1f2-5df8-4ee1-bb92-12720868582b in org d688d452-cf04-4620-84f0-3431ce4d741a
110