Git Product home page Git Product logo

cxvscode's People

Contributors

cx-muhammed avatar dependabot[bot] avatar exlegalalien avatar ghannamz avatar jyotibhalerao avatar kaplanlior avatar majdmah avatar oribendetcx avatar rahulpidde23 avatar subhadrasahoo avatar thokalsameer avatar umeshwaghode avatar yashhjaggi1998 avatar

Stargazers

 avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Forkers

fjsnogueira

cxvscode's Issues

Whenever I reopen VS Code, the Checkmarx plugin requires me to login again in order to run a scan. Error: "Access token expired. Please login again."

Whenever I reopen VS Code, the Checkmarx plugin requires me to login again in order to run a scan. How can I get the plugin to remember my login so that I don't have to keep logging in whenever I want to run a scan? Is there a way to tell if there's something wrong on my end? My colleagues have the same problem, and we need to re-login each time.

Steps

Follow the VS Code setup instructions.
Install the Checkmarx plugin and set up a CxPortal server.
Click Padlock icon, login with Credentials.
Click Book icon, bind your project.
Run a scan if you want. This scan works.

image

Close VS Code.

Open VS Code.

Try running a scan again. This error appears:

"Access token expired. Please login again."

Checkmarx console shows:

Error: Access token expired. Please login.
Sending GET request to https://checkmarx.internal/CxRestAPI/projects
GET request failed to https://checkmarx.internal/CxRestAPI/projects
Error: unable to get local issuer certificate
Sending GET request to https://checkmarx.internal/CxRestAPI/projects
GET request failed to https://checkmarx.internal/CxRestAPI/projects
Error: unable to get local issuer certificate
Error: Access token expired. Please login.

image

Now in CX Portal, click the padlock and login to Checkmarx portal again. Run a scan. It works.

Note: it doesn't matter if I set up the plugin via settings.json directly or via the UI steps. We're facing the same problem each time we reopen VS Code.

Multiple Vulnerabilities Found in Dependencies

Hello Team.

I hope you are doing well. I am reaching out to inform you of a critical security matter. After cloning the repository, I have identified several vulnerabilities across multiple dependencies. These issues range in severity.

Key Vulnerabilities identified:

Remote Code Execution (RCE) [Critical Severity][https://security.snyk.io/vuln/SNYK-JS-VM2-5772823] in [email protected]

Upgrading these dependencies will not only resolve the current vulnerabilities but will also enhance the overall security posture of the project.

"project already exists" error

Sometimes when I try to rescan a project the extension throws an error because the project already exists. I'd like to incrementally scan the same project to see the vulnerabilities decrease as I address them.

What causes this error and how can I avoid it?

Thanks!

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.