snyk-test ○ success
⏱
Duration: 15s
⏳
Queued: 2s
📁
Stage: test
🖥
Runner: linux-1
Average Duration
39s
This job: 15s
Failure Rate
0.0%
last 30 days
External Links
▶
Job Execution Phases
💡 Tip: Click on any phase bar to jump to that section in the log below
▶
Job Analysis
Job Status: Passed
Status: Job passed successfully
▶
Full Job Log
239 lines
Match - of 0
1
22:29:25
Running with gitlab-runner 18.9.0 (07e534ba)
2
22:29:25
on gitlab-runner-linux-1-5b9cfd64ff-k5sg5 aP4tCsXyp, system ID: r_wQDtEh3nNZsL
3
22:29:25
feature flags: FF_USE_FASTZIP:true, FF_USE_NEW_BASH_EVAL_STRATEGY:true, FF_USE_DYNAMIC_TRACE_FORCE_SEND_INTERVAL:true, FF_SCRIPT_SECTIONS:true, FF_ENABLE_JOB_CLEANUP:true, FF_USE_ADVANCED_POD_SPEC_CONFIGURATION:true, FF_PRINT_POD_EVENTS:true, FF_USE_DUMB_INIT_WITH_KUBERNETES_EXECUTOR:true, FF_LOG_IMAGES_CONFIGURED_FOR_JOB:true, FF_CLEAN_UP_FAILED_CACHE_EXTRACT:true, FF_GIT_URLS_WITHOUT_TOKENS:true, FF_WAIT_FOR_POD_TO_BE_REACHABLE:true, FF_USE_FLEETING_ACQUIRE_HEARTBEATS:true, FF_USE_JOB_ROUTER:true
4
22:29:25
Resolving secrets
5
22:29:25
section_start:1778279365:prepare_executor
6
22:29:25
+Preparing the "kubernetes" executor
7
22:29:25
Using Kubernetes namespace: gitlab-runner
8
22:29:25
Using Kubernetes executor with image registry.scandit.com/dockerfiles/snyk:python-3.12@sha256:2d3ac69a546de877e560310a1afe3cdeea0d4664a411ad15384c3975ea064dda ...
9
22:29:25
Using attach strategy to execute scripts...
10
22:29:25
Using effective pull policy of [Always] for container init-permissions
11
22:29:25
Using effective pull policy of [Always] for container build
12
22:29:25
Using effective pull policy of [Always] for container helper
13
22:29:25
section_end:1778279365:prepare_executor
14
22:29:25
+section_start:1778279365:prepare_script
15
22:29:25
+Preparing environment
16
22:29:25
Using FF_USE_POD_ACTIVE_DEADLINE_SECONDS, the Pod activeDeadlineSeconds will be set to the job timeout: 1h0m0s...
17
22:29:25
WARNING: Advanced Pod Spec configuration enabled, merging the provided PodSpec to the generated one. This is a beta feature and is subject to change. Feedback is collected in this issue: https://gitlab.com/gitlab-org/gitlab-runner/-/issues/29659 ...
18
22:29:25
Subscribing to Kubernetes Pod events...
19
22:29:25
Type Reason Message
20
22:29:25
Normal Scheduled Successfully assigned gitlab-runner/runner-ap4tcsxyp-project-621-concurrent-9-vs3a1l67 to ci4
21
22:29:26
Normal Pulled Container image "registry.gitlab.com/gitlab-org/gitlab-runner/gitlab-runner-helper:x86_64-v18.9.0" already present on machine
22
22:29:26
Normal Created Created container: init-permissions
23
22:29:26
Normal Started Started container init-permissions
24
22:29:26
Normal Pulled Container image "registry.gitlab.com/gitlab-org/gitlab-runner/gitlab-runner-helper:x86_64-v18.9.0" already present on machine
25
22:29:26
Normal Created Created container: helper
26
22:29:26
Normal Started Started container helper
27
22:29:26
Normal Pulling Pulling image "registry.scandit.com/dockerfiles/snyk:python-3.12@sha256:2d3ac69a546de877e560310a1afe3cdeea0d4664a411ad15384c3975ea064dda"
28
22:29:26
Normal Pulled Successfully pulled image "registry.scandit.com/dockerfiles/snyk:python-3.12@sha256:2d3ac69a546de877e560310a1afe3cdeea0d4664a411ad15384c3975ea064dda" in 193ms (193ms including waiting). Image size: 508781547 bytes.
29
22:29:26
Normal Created Created container: build
30
22:29:27
Normal Started Started container build
31
22:29:28
Running on runner-ap4tcsxyp-project-621-concurrent-9-vs3a1l67 via gitlab-runner-linux-1-5b9cfd64ff-k5sg5...
32
22:29:28
33
22:29:28
section_end:1778279368:prepare_script
34
22:29:28
+section_start:1778279368:get_sources
35
22:29:28
+Getting source from Git repository
36
22:29:29
Gitaly correlation ID: 01KR4VBE212RCSMFG6HNQ5R0MR
37
22:29:29
Fetching changes with git depth set to 50...
38
22:29:29
Initialized empty Git repository in /build/internal/gitlab-templates/.git/
39
22:29:29
Created fresh repository.
40
22:29:30
Checking out d5797a8b as detached HEAD (ref is refs/merge-requests/642/merge)...
41
22:29:30
42
22:29:30
Skipping Git submodules setup
43
22:29:30
44
22:29:30
section_end:1778279370:get_sources
45
22:29:30
+section_start:1778279370:step_script
46
22:29:30
+Executing "step_script" stage of the job script
47
22:29:30
section_start:1778279370:section_pre_build_script_0[hide_duration=true,collapsed=true]
$ function cleanup {
48
22:29:30
rv=$?
49
22:29:30
if [ $rv -ne 0 ]; then
50
22:29:30
echo ""
51
22:29:30
echo " Failure Cause Analysis might help, please open this link:"
52
22:29:30
echo " https://scout.scandit.io/analysis/projects/${CI_PROJECT_ID}/jobs/${CI_JOB_ID}"
53
22:29:30
echo ""
54
22:29:30
fi
55
22:29:30
echo ""
56
22:29:30
echo "Scout Analysis: https://scout.scandit.io/analysis/projects/${CI_PROJECT_ID}/jobs/${CI_JOB_ID}"
57
22:29:30
echo ""
58
22:29:30
echo ""
59
22:29:30
echo "Grafana Pod-View: https://grafana.scandit.com/d/k8s_views_pods/kubernetes-views-pods?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-host=${SC_K8S_NODE_NAME}&var-namespace=${SC_K8S_NAMESPACE}&var-pod=${HOSTNAME}&var-resolution=15&from=${__start_time}000&to=${EPOCHSECONDS}000"
60
22:29:30
echo "Grafana Node-View: https://grafana.scandit.com/d/k8s_views_nodes/kubernetes-views-nodes?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-node=${SC_K8S_NODE_NAME}&var-resolution=15s&from=${__start_time}000&to=${EPOCHSECONDS}000"
61
22:29:30
echo "Loki Logs: https://grafana.scandit.com/a/grafana-lokiexplore-app/explore/log_group/gitlab-runner/logs?var-ds=${LOKI_DATASOURCE}&var-filters=log_group%7C=%7Cgitlab-runner&var-filters=source%7C%3D%7C${LOKI_LOGSOURCE}&var-filters=namespace%7C%3D%7C${SC_K8S_NAMESPACE}&var-filters=CI_PROJECT_ID%7C%3D%7C${CI_PROJECT_ID}&var-filters=CI_PIPELINE_ID%7C%3D%7C${CI_PIPELINE_ID}&var-filters=CI_JOB_ID%7C%3D%7C${CI_JOB_ID}&sortOrder=Ascending&from=${__start_time}000&to=${EPOCHSECONDS}000"
62
22:29:30
__date_from=$(date -d "@$(( EPOCHSECONDS - 604800 ))" +%Y-%m-%d)
63
22:29:30
__date_to=$(date -d "@$(( EPOCHSECONDS + 604800 ))" +%Y-%m-%d)
64
22:29:30
echo "Lilibet Statistics: https://lilibet.scandit.io/dashboard/204-job-drill-down?date_range=${__date_from}~${__date_to}&job_name=${CI_JOB_NAME}&project=${CI_PROJECT_PATH}"
65
22:29:30
echo ""
66
22:29:30
exit $rv
67
22:29:30
}
68
22:29:30
trap cleanup EXIT
69
22:29:30
echo "INFO: This is the CI job pre_build_script"
70
22:29:30
echo "INFO: It's defined in the backend/infra/onprem/k8s repo."
71
22:29:30
echo "INFO: These additional Scandit variables are available to you:"
72
22:29:30
echo " SC_K8S_NODE_NAME: $SC_K8S_NODE_NAME"
73
22:29:30
echo " SC_K8S_IMAGE_ID: $SC_K8S_IMAGE_ID"
74
22:29:30
echo " SC_K8S_KYVERNO_PATCHES: |"
75
22:29:30
echo "$SC_K8S_KYVERNO_PATCHES" | sed 's/^/ /'
76
22:29:30
echo "cpu (r/l): ${SC_K8S_REQUESTS_CPU}/${SC_K8S_LIMITS_CPU}"
77
22:29:30
if command -v numfmt >/dev/null 2>&1; then
78
22:29:30
echo "memory (r/l): $(numfmt --to=iec --suffix=B $SC_K8S_REQUESTS_MEMORY)/$(numfmt --to=iec --suffix=B $SC_K8S_LIMITS_MEMORY)"
79
22:29:30
else
80
22:29:30
echo "memory (r/l): ${SC_K8S_REQUESTS_MEMORY}/${SC_K8S_LIMITS_MEMORY}"
81
22:29:30
fi
82
22:29:30
__start_time=${EPOCHSECONDS}
83
22:29:30
echo ""
84
22:29:30
echo "Grafana Pod-View: https://grafana.scandit.com/d/k8s_views_pods/kubernetes-views-pods?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-host=${SC_K8S_NODE_NAME}&var-namespace=${SC_K8S_NAMESPACE}&var-pod=${HOSTNAME}&var-resolution=15&from=${__start_time}000&to=now"
85
22:29:30
echo "Grafana Node-View: https://grafana.scandit.com/d/k8s_views_nodes/kubernetes-views-nodes?orgId=1&refresh=1m&var-datasource=${GRAFANA_DATASOURCE}&var-node=${SC_K8S_NODE_NAME}&var-resolution=15s&from=${__start_time}000&to=now"
86
22:29:30
echo "Loki Logs: https://grafana.scandit.com/a/grafana-lokiexplore-app/explore/log_group/gitlab-runner/logs?var-ds=${LOKI_DATASOURCE}&var-filters=log_group%7C%3D%7Cgitlab-runner&var-filters=source%7C%3D%7C${LOKI_LOGSOURCE}&var-filters=namespace%7C%3D%7C${SC_K8S_NAMESPACE}&var-filters=CI_PROJECT_ID%7C%3D%7C${CI_PROJECT_ID}&var-filters=CI_PIPELINE_ID%7C%3D%7C${CI_PIPELINE_ID}&var-filters=CI_JOB_ID%7C%3D%7C${CI_JOB_ID}&sortOrder=Ascending&from=${__start_time}000&to=now"
87
22:29:30
__date_from=$(date -d "@$(( EPOCHSECONDS - 604800 ))" +%Y-%m-%d)
88
22:29:30
__date_to=$(date -d "@$(( EPOCHSECONDS + 604800 ))" +%Y-%m-%d)
89
22:29:30
echo "Lilibet Statistics: https://lilibet.scandit.io/dashboard/204-job-drill-down?date_range=${__date_from}~${__date_to}&job_name=${CI_JOB_NAME}&project=${CI_PROJECT_PATH}"
90
22:29:30
echo ""
91
22:29:30
echo "Setting up credentials for Gitlab Python registries"
92
22:29:30
mkdir -p ~
93
22:29:30
echo "machine gitlab.scandit.com" > ~/.netrc
94
22:29:30
echo "login gitlab-ci-token" >> ~/.netrc
95
22:29:30
echo "password ${CI_JOB_TOKEN}" >> ~/.netrc
96
22:29:30
chmod 600 ~/.netrc
97
22:29:30
if command -v git &> /dev/null && [ "$(id -u)" -ne 0 ]; then
98
22:29:30
git config --global --add safe.directory $CI_PROJECT_DIR
99
22:29:30
fi
100
22:29:30
sleep infinity &
101
22:29:30
echo $! > ~/.bg_pid
102
22:29:30
section_end:1778279370:section_pre_build_script_0
103
22:29:30
INFO: This is the CI job pre_build_script
104
22:29:30
INFO: It's defined in the backend/infra/onprem/k8s repo.
105
22:29:30
INFO: These additional Scandit variables are available to you:
106
22:29:30
SC_K8S_NODE_NAME: ci4
107
22:29:30
SC_K8S_IMAGE_ID:
108
22:29:30
SC_K8S_KYVERNO_PATCHES: |
109
22:29:30
110
22:29:30
cpu (r/l): 1/8
111
22:29:30
memory (r/l): 1.0GB/16GB
112
22:29:30
113
22:29:30
Grafana Pod-View: https://grafana.scandit.com/d/k8s_views_pods/kubernetes-views-pods?orgId=1&refresh=1m&var-datasource=KpIiby5Vz&var-host=ci4&var-namespace=gitlab-runner&var-pod=runner-ap4tcsxyp-project-621-concurrent-9-vs3a1l67&var-resolution=15&from=1778279370000&to=now
114
22:29:30
Grafana Node-View: https://grafana.scandit.com/d/k8s_views_nodes/kubernetes-views-nodes?orgId=1&refresh=1m&var-datasource=KpIiby5Vz&var-node=ci4&var-resolution=15s&from=1778279370000&to=now
115
22:29:30
Loki Logs: https://grafana.scandit.com/a/grafana-lokiexplore-app/explore/log_group/gitlab-runner/logs?var-ds=nVsAo7UVk&var-filters=log_group%7C%3D%7Cgitlab-runner&var-filters=source%7C%3D%7Czrh.int.scandit.io&var-filters=namespace%7C%3D%7Cgitlab-runner&var-filters=CI_PROJECT_ID%7C%3D%7C621&var-filters=CI_PIPELINE_ID%7C%3D%7C1586734&var-filters=CI_JOB_ID%7C%3D%7C54740777&sortOrder=Ascending&from=1778279370000&to=now
116
22:29:30
Lilibet Statistics: https://lilibet.scandit.io/dashboard/204-job-drill-down?date_range=2026-05-01~2026-05-15&job_name=snyk-test&project=internal/gitlab-templates
117
22:29:30
118
22:29:30
Setting up credentials for Gitlab Python registries
119
22:29:30
$ uv pip install --system -r requirements.txt
120
22:29:31
Using Python 3.12.13 environment at: /usr/local
121
22:29:31
Resolved 7 packages in 564ms
122
22:29:31
Downloading pygments (1.2MiB)
123
22:29:31
Downloaded pygments
124
22:29:31
Prepared 7 packages in 202ms
125
22:29:31
Installed 7 packages in 20ms
126
22:29:31
+ coverage==7.13.5
127
22:29:31
+ iniconfig==2.3.0
128
22:29:31
+ packaging==26.2
129
22:29:31
+ pluggy==1.6.0
130
22:29:31
+ pygments==2.20.0
131
22:29:31
+ pytest==9.0.3
132
22:29:31
+ pytest-cov==7.1.0
133
22:29:31
section_start:1778279371:section_script_step_1[hide_duration=true,collapsed=true]
$ set -e
134
22:29:31
135
22:29:31
function log_info() {
136
22:29:31
echo -e "[\e[1;94mINFO\e[0m] $*"
137
22:29:31
}
138
22:29:31
139
22:29:31
function log_warn() {
140
22:29:31
echo -e "[\e[1;93mWARN\e[0m] $*"
141
22:29:31
}
142
22:29:31
143
22:29:31
function log_error() {
144
22:29:31
echo -e "[\e[1;91mERROR\e[0m] $*"
145
22:29:31
}
146
22:29:31
147
22:29:31
function fail() {
148
22:29:31
log_error "$*"
149
22:29:31
exit 1
150
22:29:31
}
151
22:29:31
152
22:29:31
function assert_defined() {
153
22:29:31
if [[ -z "$1" ]]
154
22:29:31
then
155
22:29:31
log_error "$2"
156
22:29:31
exit 1
157
22:29:31
fi
158
22:29:31
}
159
22:29:31
160
22:29:31
function snyk_setup() {
161
22:29:31
# If SNYK_FILE is set, use it as a target, otherwise use --all-projects
162
22:29:31
if [[ -n "${SNYK_FILE}" ]]; then
163
22:29:31
SNYK_TARGET="--file=${SNYK_FILE}"
164
22:29:31
else
165
22:29:31
SNYK_TARGET="--all-projects"
166
22:29:31
fi
167
22:29:31
168
22:29:31
log_info "Targeting $SNYK_TARGET"
169
22:29:31
170
22:29:31
# Set log level based on SNYK_LOG_LEVEL
171
22:29:31
if [[ "$SNYK_LOG_LEVEL" == "info" ]]; then
172
22:29:31
SNYK_LOG_LEVEL=""
173
22:29:31
elif [[ "$SNYK_LOG_LEVEL" == "debug" ]]; then
174
22:29:31
SNYK_LOG_LEVEL="--debug"
175
22:29:31
elif [[ "$SNYK_LOG_LEVEL" == "trace" ]]; then
176
22:29:31
SNYK_LOG_LEVEL="--debug --log-level=trace"
177
22:29:31
fi
178
22:29:31
}
179
22:29:31
section_end:1778279371:section_script_step_1
180
22:29:31
$ assert_defined "$SNYK_TOKEN" "No SNYK_TOKEN defined. You have to provide a valid token for accessing Snyk."
181
22:29:31
$ snyk_setup
182
22:29:31
[INFO] Targeting --file=requirements.txt
183
22:29:31
$ set -x
184
22:29:31
++ echo '$ snyk $SNYK_COMMAND $SNYK_TARGET --org=$SNYK_ORG --remote-repo-url=$SNYK_REMOTE_REPO_URL --policy-path=$SNYK_POLICY_PATH ${SNYK_EXCLUDE:+--exclude=$SNYK_EXCLUDE} ${SNYK_TARGET_REFERENCE:+--target-reference=$SNYK_TARGET_REFERENCE} ${SNYK_PROJECT_ENVIRONMENT:+--project-environment=$SNYK_PROJECT_ENVIRONMENT} ${SNYK_PROJECT_LIFECYCLE:+--project-lifecycle=$SNYK_PROJECT_LIFECYCLE} ${SNYK_PROJECT_TAGS:+--project-tags=$SNYK_PROJECT_TAGS} $SNYK_LOG_LEVEL $SNYK_EXTRA_PARAMETERS'
185
22:29:31
$ snyk $SNYK_COMMAND $SNYK_TARGET --org=$SNYK_ORG --remote-repo-url=$SNYK_REMOTE_REPO_URL --policy-path=$SNYK_POLICY_PATH ${SNYK_EXCLUDE:+--exclude=$SNYK_EXCLUDE} ${SNYK_TARGET_REFERENCE:+--target-reference=$SNYK_TARGET_REFERENCE} ${SNYK_PROJECT_ENVIRONMENT:+--project-environment=$SNYK_PROJECT_ENVIRONMENT} ${SNYK_PROJECT_LIFECYCLE:+--project-lifecycle=$SNYK_PROJECT_LIFECYCLE} ${SNYK_PROJECT_TAGS:+--project-tags=$SNYK_PROJECT_TAGS} $SNYK_LOG_LEVEL $SNYK_EXTRA_PARAMETERS
186
22:29:31
++ snyk test --file=requirements.txt --org=d688d452-cf04-4620-84f0-3431ce4d741a --remote-repo-url=internal/gitlab-templates --policy-path=/build/internal/gitlab-templates/.snyk
187
22:29:38
188
22:29:38
Testing /build/internal/gitlab-templates...
189
22:29:38
190
22:29:38
Organization: scandit-internal
191
22:29:38
Package manager: pip
192
22:29:38
Target file: requirements.txt
193
22:29:38
Project name: gitlab-templates
194
22:29:38
Open source: no
195
22:29:38
Project path: /build/internal/gitlab-templates
196
22:29:38
Local Snyk policy: found
197
22:29:38
Licenses: enabled
198
22:29:38
199
22:29:38
✔ Tested 7 dependencies for known issues, no vulnerable paths found.
200
22:29:38
201
22:29:38
Tip: Detected multiple supported manifests (2), use --all-projects to scan all of them at once.
202
22:29:38
203
22:29:38
204
22:29:38
++ echo '$ set +x'
205
22:29:38
$ set +x
206
22:29:38
++ set +x
207
22:29:38
208
22:29:38
Scout Analysis: https://scout.scandit.io/analysis/projects/621/jobs/54740777
209
22:29:38
210
22:29:38
211
22:29:38
Grafana Pod-View: https://grafana.scandit.com/d/k8s_views_pods/kubernetes-views-pods?orgId=1&refresh=1m&var-datasource=KpIiby5Vz&var-host=ci4&var-namespace=gitlab-runner&var-pod=runner-ap4tcsxyp-project-621-concurrent-9-vs3a1l67&var-resolution=15&from=1778279370000&to=1778279378000
212
22:29:38
Grafana Node-View: https://grafana.scandit.com/d/k8s_views_nodes/kubernetes-views-nodes?orgId=1&refresh=1m&var-datasource=KpIiby5Vz&var-node=ci4&var-resolution=15s&from=1778279370000&to=1778279378000
213
22:29:38
Loki Logs: https://grafana.scandit.com/a/grafana-lokiexplore-app/explore/log_group/gitlab-runner/logs?var-ds=nVsAo7UVk&var-filters=log_group%7C=%7Cgitlab-runner&var-filters=source%7C%3D%7Czrh.int.scandit.io&var-filters=namespace%7C%3D%7Cgitlab-runner&var-filters=CI_PROJECT_ID%7C%3D%7C621&var-filters=CI_PIPELINE_ID%7C%3D%7C1586734&var-filters=CI_JOB_ID%7C%3D%7C54740777&sortOrder=Ascending&from=1778279370000&to=1778279378000
214
22:29:38
Lilibet Statistics: https://lilibet.scandit.io/dashboard/204-job-drill-down?date_range=2026-05-01~2026-05-15&job_name=snyk-test&project=internal/gitlab-templates
215
22:29:38
216
22:29:38
217
22:29:38
section_end:1778279378:step_script
218
22:29:38
+section_start:1778279378:after_script
219
22:29:38
+Running after_script
220
22:29:39
Running after script...
221
22:29:39
section_start:1778279379:section_after_script_step_0[hide_duration=true,collapsed=true]
$ cat <<-EOD
222
22:29:39
----------------------------------------------------------
223
22:29:39
Need help? Documentation on the Snyk jobs can be found at:
224
22:29:39
https://gitlab.scandit.com/internal/gitlab-templates/-/blob/master/.gitlab/snyk.md
225
22:29:39
EOD
226
22:29:39
section_end:1778279379:section_after_script_step_0
227
22:29:39
----------------------------------------------------------
228
22:29:39
Need help? Documentation on the Snyk jobs can be found at:
229
22:29:39
https://gitlab.scandit.com/internal/gitlab-templates/-/blob/master/.gitlab/snyk.md
230
22:29:39
231
22:29:39
section_end:1778279379:after_script
232
22:29:39
+section_start:1778279379:cleanup_file_variables
233
22:29:39
+Cleaning up project directory and file based variables
234
22:29:39
HEAD is now at d5797a8 Merge branch 'renovate/docker-digests' into 'master'
235
22:29:39
236
22:29:39
section_end:1778279379:cleanup_file_variables
237
22:29:39
+
238
22:29:39
Job succeeded
239