Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scorecards supply-chain security/Scorecards analysis workflow failing on main branch #490

Closed
aramase opened this issue Dec 13, 2022 · 3 comments

Comments

@aramase
Copy link
Collaborator

aramase commented Dec 13, 2022

Error details: instance.runs[2].tool.driver.rules contains duplicate item
Error: Unable to upload "results.sarif" as it is not valid SARIF:
- instance.runs[2].tool.driver.rules contains duplicate item
Error: Unable to upload "results.sarif" as it is not valid SARIF:
- instance.runs[2].tool.driver.rules contains duplicate item
    at validateSarifFileSchema (/home/runner/work/_actions/github/codeql-action/a669cc5936cc5e1b6a362ec1ff9e410dc570d190/lib/upload-lib.js:189:15)
    at uploadFiles (/home/runner/work/_actions/github/codeql-action/a669cc5936cc5e1b6a362ec1ff9e410dc570d190/lib/upload-lib.js:238:9)
    at Object.uploadFromActions (/home/runner/work/_actions/github/codeql-action/a669cc5936cc5e1b6a362ec1ff9e410dc570d190/lib/upload-lib.js:132:18)
    at async run (/home/runner/work/_actions/github/codeql-action/a669cc5936cc5e1b6a362ec1ff9e410dc570d190/lib/upload-sarif-action.js:46:30)
    at async runWrapper (/home/runner/work/_actions/github/codeql-action/a669cc5936cc5e1b6a362ec1ff9e410dc570d190/lib/upload-sarif-action.js:68:9)

ref: https://github.com/deislabs/ratify/actions/runs/3681413597/jobs/6228071212

@akashsinghal
Copy link
Collaborator

Opened an issue on OSSF/scorecard-action repo for help: ossf/scorecard-action#1076

@akashsinghal
Copy link
Collaborator

Update: This issue cannot be replicated on any other branch for the repository. ossf maintainer cannot help further debug if it's not reproducible. They would require us to alter our main branch directly to collect more diagnostic logs and I don't know if we want to take such a drastic step.

@akashsinghal
Copy link
Collaborator

Update: issue in the main scorecard logic has been identified. Tracking issue upstream: ossf/scorecard#2686

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants