Skip to content

fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands - #8006

Closed
cx-andre-pereira wants to merge 197 commits into
Checkmarx:masterfrom
cx-andre-pereira:Dockerfile_queries_fix_for_case_insensitivity
Closed

cx-andre-pereira wants to merge 197 commits into
Checkmarx:masterfrom
cx-andre-pereira:Dockerfile_queries_fix_for_case_insensitivity

Conversation

@cx-andre-pereira

@cx-andre-pereira cx-andre-pereira commented Mar 23, 2026 •

Copy link
Copy Markdown
Contributor

Reason for Proposed Changes

The changes from #7995 (included in this PR) enable scanned Dockerfiles to recognize valid case-insensitive syntax. However, none of the existing Dockerfile queries were prepared for this — all of them contain hardcoded uppercase references to Docker commands.

Additionally, testing revealed that the existing query logic, payload generation, and engine line-searching logic did not support multiple FROM statements associated with the same image within a single document. In such cases, only the first FROM statement would produce results; the engine was unable to flag any subsequent occurrences.

Proposed Changes


New auxiliary functions

Two new helper functions were added to the common library dockerfile.rego:

  • get_original_from_command — Extracts the FROM command with its original casing along with the LineHint value for that command.
  • add_line_hint — Appends the extracted LineHint to the string using ^ as a separator.

The LineHint value enables the engine to distinguish between multiple FROM statements referencing the same image.


Query updates

  • All queries now use these two auxiliary functions to generate their searchKey value. On the engine side, preserving the original casing of FROM enables more precise searching through the source file. The LineHint value is consumed by docker_detect and stripped by the vulnerability_builder before results are emitted.

Parser changes

  • The parser was updated so that each FROM statement generates a distinct object. Previously, all FROM commands referencing the same image were merged into a single object.

Test coverage

  • A new positive and negative sample was added to every test folder. These mirror the existing positive/positive1 and negative/negative1 tests but use all-lowercase commands.

  • A new E2E test (107) was added, it tests that the payload/results of a scan on a multistage dockerfile sample with duplicate FROM statements is parsed/flagged as expected.

  • New test based on OriginalData4 added to the docker_detect_test file, also checks that a multistage sample with duplicate FROM statements flags properly.

  • TestDockerSearchKeyLineHintRemoval was added to the vulnerability_builder_test file, as the name implies it checks that the LineHint appended to the searchKey value of a sample dockefile query is removed properly.


Updated Documentation/Script

  • The query creation documentation was updated to reflect these changes, specifically for Dockerfile query searchKey value attribution.
  • The validate_search_line.py CI script was updated to account for the fact that Dockerfile queries do not currently support searchLine values. The script now excludes all queries under the dockerfile queries folder.

I submit this contribution under the Apache-2.0 license.

@github-actions github-actions Bot added community Community contribution query New query feature dockerfile labels Mar 23, 2026
@cx-andre-pereira cx-andre-pereira changed the title Dockerfile queries fix for case insensitivity fix(query): changed all dockerfile queries for case insensitivity support Mar 23, 2026
@cx-andre-pereira cx-andre-pereira changed the title fix(query): changed all dockerfile queries for case insensitivity support fix(query): changed all dockerfile queries for case insensitive support of docker configurations Mar 23, 2026
@cx-andre-pereira cx-andre-pereira changed the title fix(query): changed all dockerfile queries for case insensitive support of docker configurations fix(query): changed all dockerfile queries for case insensitive support of docker commands Mar 23, 2026
@github-actions github-actions Bot added the docker Docker query label Mar 23, 2026
@cx-andre-pereira cx-andre-pereira changed the title fix(query): changed all dockerfile queries for case insensitive support of docker commands fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands Mar 24, 2026
@cx-andre-pereira
cx-andre-pereira marked this pull request as ready for review April 2, 2026 11:31
@cx-andre-pereira
cx-andre-pereira requested a review from a team as a code owner April 2, 2026 11:31
@cx-andre-pereira
cx-andre-pereira force-pushed the Dockerfile_queries_fix_for_case_insensitivity branch from db1b7e2 to 47b647e Compare April 7, 2026 22:28
@cx-andre-pereira
cx-andre-pereira force-pushed the Dockerfile_queries_fix_for_case_insensitivity branch from c705f07 to a500e92 Compare July 8, 2026 13:50
cx-artur-ribeiro and others added 16 commits July 28, 2026 18:16
…or multiple volumes cases (Checkmarx#7947)

* fix EFS Volume With Disabled Transit Encryption query for multiple volumes cases in tf and cf

* update: dockerfile images
…x#7997)

* add bad utf conversions to unwanted in analyzer

* add bad utf conversions to unwanted in analyzer

* update e2e tests and uts to cover valid ansible samples

* update base images

---------

Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com>
Updated Trivy action version from v0.34.2 to v0.35.0 in both scanning steps.
* update: login to DockerHub to token

* bump: kics github action version
* add arm64 testing infra

* add arm64 testing infra

* bump images

* ci

* update e2e infra

* update e2e infra

* improve docker ubi 8 to support arm

* improve docker ubi 8 to support arm

* improve docker ubi 8 to support arm

* improve docker ubi 8 to support arm

* fix vulnerabilities

* fix vulnerabilities

* fix vulnerabilities

* fix vulnerabilities

* fix vulnerabilities

---------

Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com>
Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
Checkmarx#7955)

* first commit

* rewrite previous changes

* causing remediation error on purpose

* some changes

* .

* .

* added remediatedFiles to error output in remediation tests

* restored directories removed by mistake

* removed files

* Delete assets/queries/terraform/aws/api_gateway_access_logging_disabled/payloads/all_payloads.json

* Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads/all_payloads.json

* Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads directory

* Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/samples/sample.tf

* Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads directory

* Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads directory

* Delete assets/queries/terraform/gcp/google_kubernetes_engine_cluster_have_alpha_features_enabled/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads/test_payload.json

* Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads directory

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads directory

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/test/test.tf

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/payloads directory

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads/positive1_payload.json

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads directory

* Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads directory

* Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test/negative.tf

* Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test directory

* Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled directory

* added remediation problems to the query

* fixed golint problems

* golint

* change on the query

* fixing line that surpasses the 140 characters limits by go-ci/lint

* .

* changed e2e test to see HTML results output

* .

* .

* .

* removed one query in the results

* indenting json output on E2E test HTML report

* changed fixture results

* changed comparison using listA and list B, to Expected and Actual lists

* some changes on the json output

* reverted changes on E2E results outputs

* put listA and listB side by side

* fully implemented red line for diff line

* added queryName in the output

* final improvement on HTML E2E test results output

* removed unnecessary comment

* revert changes made on E2E fixtures

* reverted changes on E2E files

* reverted changes on E2E files

* reverted changes on the wrong go template file

* fixing go lint errors

* fixing go lint error

* go lint error fixing

* go lint error fixing

* go lint error fixing

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* keeping up with the codacy quality standards

* improvements on the code

* trimmed lines before direct comparisons

* adding the e2e-report file again

* changing google.golang.org/grpc version from 1.77.0 to 1.79.3

* fixed analyze command in e2e test

* covered FileStats field comparison on e2e tests

* reverting changes made on analyze.go file

* changed moby/buildkit version from 0.26.3 to 0.28.1

* revert changes

* changed moby/buildkit version from 0.26.3 to 0.28.1

* fixing unproperly formatted code

* fixed path

* fixed unproperly formatted code

* removed commented code

* fixed some E2E tests not showing the intended output format

* final fix for the tests that are currently without the proper HTML report output format

* changing code to reduce cyclomatic complexity

* fixing code to be properly formatted

* removed unnecessary printf's

* fixing the code using gofmt

* changed github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream and github.com/aws/aws-sdk-go-v2/service/s3 version in go.mod

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
* Update github action to use SHA

* Update vulnerable dependency

* Update dockerfiles to use go 1.26.2

* Rollback go.mod to 1.25.5

* Fix vulnerabilities

* Fix vulnerabilities

* Update go version

* Suppress vulnerability

* Update dockerfile

* Update .grype.yaml

Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com>

* Small update

---------

Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com>
…marx#7994)

* changed go-ci.yml to use a script to check searchLine

* .

* fixed print to not use f when is missing placeholders

* removed unnecessary action

* fixed typo

* fixing issues from codacy

* updated go image in Dockerfile

* update go images

* changed git image

* changing positive expected results

* added requests to requirements file

* changed searchLine to get -1 value

* added debug prints

* added exception type

* fixing error in script

* removed trailing whitespace

* changed to run the other script

* debugging test directory path

* changed scripts that run on the action

* removed f-string without placeholders

* inverted changes on the query

* changed positive_expected_result

* changed filename to fileName

* added print for debugging processes

* added print to see content value

* changed script

* testing searchLine != searchLine

* removed unnecessary sorting on the results in execution context

* removed unused requirements.txt file

* reverter changes on positie_expected_results

* changes on the script and removed unnecessary go setup

* changed query to get errors on go-ci action

* parsing json data into objects

* small change to test if this is the root of the problem

* reverted changes

* fixing misspelled directory name

* fixing some errors in the script used in the validate-search-line job in go-ci action

* fixed misspelled field in validate_scan_results function

* simplifying code

* using pymarshal to use models that unmarshal json content directly

* fixing errors in results_models pymarshal import

* testing searchLine defined to '-1' hardcoded value

* convert line and searchLine to int

* adding print's for debug purposes

* adding print's for debug purposes

* fixing cases where searchLine is defined to an hardcoded value of -1

* added prints for debug purposes

* debug prints

* debug prints

* debug prints

* changes for debug purposes

* .

* changes

* trying to fix cases with -1 hardcoded on searchLine

* changes

* more changes

* trying type_assert

* trying type_assert

* trying type_assert

* trying type_assert

* trying type_assert

* testing new scenario

* testing test3 case from artur test branch

* testing test3 case from artur test branch

* back to the other scenario

* back to the other scenario again

* used unmarshal_json from pumarshal to unmarshal the json with the results

* testing hardcoded .1 again

* trying case - common_lib.build_search_line([shdfosdhfoisdhf], []),

* reverting changes on dockerfiles

* removed the usage of type_assert to be more permissive about fields not defined on the results file

* changed to see other case output in the actions

* added field queries_failed_to_execute

* changing query searchLine field to test another scenario

* changed to another scenario

* reverting changes made on the query

* changed to test scenario when "searchLine": common_lib.build_search_line(["potatos"], [])

* testing scenario where searchLine is defined to '-1'

* removed unnecessary pymarshal pip instalation

* testing another scenario

* testing searchLine defined to '-1'

* testing searchLine defined to 'potatos'

* reverting query changezs

* reverting changes on query

* reverting changes on docker files

* reverting changes on dockerfiles

* removed \n

* adding debug prints to see the output from variables produced by dorny/path

* added \n

* added echo for debug purposes

* Reverting changes on Dockerfile

* adding print on script

* testing outcome

* using Set Up python step outcome value to define if validate search line in modified queries runs or not

* changing go-jose version

* changing script code to match Codacy best practices

* changing code to comply with the Codacy quality standards

* changing go.mod

* fixing Codacy issues

* changing Go and Git images on Dockerfile

* changing go.mod

* reverting changes on go.mod

* changing go version

* fixing scripts according to Codacy issues

* fixing script to be up to the Codacy quality standards

* fixing Codacy issues

* fixing Codacy issues

* fixing Codacy issues

* fixing D212 in validate_search_line.py file

* reverting changes to fix D212

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
* Change to use actions role

* Update run-projects.yaml
* ci: fix aws secrets

* ci: fix permissions

* ci: remove audience

* ci: test gh token

* ci: use sha
…n" CloudFormation and Terraform queries (Checkmarx#8030)

* Added missing check/associated tests to cloudFormation and Terraform iam_policy data exfiltration queries

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
…Checkmarx#8076)

* update: dockerfile and fix vulnerabilities

* update: dockerfile with arguments before both FROM for universal scope

* update: vulnerable packages and dockerfile images

* ci: trigger

* fix: dockerfile deprecation notice for LegacyKeyValueFormat
cx-andre-pereira and others added 19 commits July 28, 2026 18:26
…ine FROM statements are compatible, fixed whitespace support for ARG/comments in dockerfiles and fix new E2E results
* fix insecure temp file

* fix insecure temp file perms

* add path traversal sanitation

* add path traversal sanitization

* add path traversal sanitization tests

* add path traversal sanitization e2e tests

* add path traversal sanitization e2e tests

* fix lint issues

* fix secrets inspector possible resource exhaustion

* fix secrets line detection for end of document specific case

* bump deps and actions versions

* bump deps and actions versions

* [StepSecurity] Apply security best practices (Checkmarx#8060)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* [StepSecurity] Apply security best practices (Checkmarx#8063)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* chore: remove Dependabot configuration

* Remove old SBOM (Checkmarx#8071)

Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>

* fix(vulnerabilities): update dockerfile and fix trivy vulnerabilities (Checkmarx#8076)

* update: dockerfile and fix vulnerabilities

* update: dockerfile with arguments before both FROM for universal scope

* update: vulnerable packages and dockerfile images

* ci: trigger

* fix: dockerfile deprecation notice for LegacyKeyValueFormat

---------

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Co-authored-by: Ohad Israeli <243351248+cx-ohad-israeli@users.noreply.github.com>
Co-authored-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
…ng (Checkmarx#8085)

* fixs for ast 154904, loop on RUN commands and 2 unrelated queries changed

* Fixed unnecessary space affecting distance calculation/ line in vulnerability result

* Update packages again
…ry to handle 'require_ssl' field deprecation (Checkmarx#8029)

* First commit: udpated query to handle deprecation of 'require_ssl' field, support for all 'ssl_mode' field values, new tests and metadata Url updated

* Small change to comments for consistency sake

* New samples and auxiliary functions to properly handle SQLSERVER databases (do not support 'TRUSTED_CLIENT_CERTIFICATE_REQUIRED' value

* Expected values and some test changes

* Fix expected results again

---------

Co-authored-by: Alon Rosenhek <80337069+cx-alon-rosenhek@users.noreply.github.com>
… accounting for specific digest values (Checkmarx#8033)

* Fix check for ':latest' to ensure it is used as a sufix on the image reference (no @sha...)

* feat(tests): improving E2E HTML report and output on remediation tests (Checkmarx#7955)

* first commit

* rewrite previous changes

* causing remediation error on purpose

* some changes

* .

* .

* added remediatedFiles to error output in remediation tests

* restored directories removed by mistake

* removed files

* Delete assets/queries/terraform/aws/api_gateway_access_logging_disabled/payloads/all_payloads.json

* Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads/all_payloads.json

* Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/payloads directory

* Delete assets/queries/terraform/aws/sns_topic_is_publicly_accessible/samples/sample.tf

* Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/ensure_essential_contacts_is_configured_for_organization/payloads directory

* Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels/payloads directory

* Delete assets/queries/terraform/gcp/google_kubernetes_engine_cluster_have_alpha_features_enabled/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads/test_payload.json

* Delete assets/queries/terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects/payloads directory

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_audit_configuration_changes/payloads directory

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/test/test.tf

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_custom_role_changes/payloads directory

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads/positive1_payload.json

* Delete assets/queries/terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes/payloads directory

* Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads/all_payloads.json

* Delete assets/queries/terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled/payloads directory

* Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test/negative.tf

* Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled/test directory

* Delete assets/queries/terraform/gcp/sql_db_instance_external_scripts_enabled directory

* added remediation problems to the query

* fixed golint problems

* golint

* change on the query

* fixing line that surpasses the 140 characters limits by go-ci/lint

* .

* changed e2e test to see HTML results output

* .

* .

* .

* removed one query in the results

* indenting json output on E2E test HTML report

* changed fixture results

* changed comparison using listA and list B, to Expected and Actual lists

* some changes on the json output

* reverted changes on E2E results outputs

* put listA and listB side by side

* fully implemented red line for diff line

* added queryName in the output

* final improvement on HTML E2E test results output

* removed unnecessary comment

* revert changes made on E2E fixtures

* reverted changes on E2E files

* reverted changes on E2E files

* reverted changes on the wrong go template file

* fixing go lint errors

* fixing go lint error

* go lint error fixing

* go lint error fixing

* go lint error fixing

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* fixing go lint errors

* keeping up with the codacy quality standards

* improvements on the code

* trimmed lines before direct comparisons

* adding the e2e-report file again

* changing google.golang.org/grpc version from 1.77.0 to 1.79.3

* fixed analyze command in e2e test

* covered FileStats field comparison on e2e tests

* reverting changes made on analyze.go file

* changed moby/buildkit version from 0.26.3 to 0.28.1

* revert changes

* changed moby/buildkit version from 0.26.3 to 0.28.1

* fixing unproperly formatted code

* fixed path

* fixed unproperly formatted code

* removed commented code

* fixed some E2E tests not showing the intended output format

* final fix for the tests that are currently without the proper HTML report output format

* changing code to reduce cyclomatic complexity

* fixing code to be properly formatted

* removed unnecessary printf's

* fixing the code using gofmt

* changed github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream and github.com/aws/aws-sdk-go-v2/service/s3 version in go.mod

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>

* fix(workflows): update github actions to use SHA (Checkmarx#8035)

* Update github action to use SHA

* Update vulnerable dependency

* Update dockerfiles to use go 1.26.2

* Rollback go.mod to 1.25.5

* Fix vulnerabilities

* Fix vulnerabilities

* Update go version

* Suppress vulnerability

* Update dockerfile

* Update .grype.yaml

Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com>

* Small update

---------

Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com>

* feat(action): added validation for searchLine field in actions (Checkmarx#7994)

* changed go-ci.yml to use a script to check searchLine

* .

* fixed print to not use f when is missing placeholders

* removed unnecessary action

* fixed typo

* fixing issues from codacy

* updated go image in Dockerfile

* update go images

* changed git image

* changing positive expected results

* added requests to requirements file

* changed searchLine to get -1 value

* added debug prints

* added exception type

* fixing error in script

* removed trailing whitespace

* changed to run the other script

* debugging test directory path

* changed scripts that run on the action

* removed f-string without placeholders

* inverted changes on the query

* changed positive_expected_result

* changed filename to fileName

* added print for debugging processes

* added print to see content value

* changed script

* testing searchLine != searchLine

* removed unnecessary sorting on the results in execution context

* removed unused requirements.txt file

* reverter changes on positie_expected_results

* changes on the script and removed unnecessary go setup

* changed query to get errors on go-ci action

* parsing json data into objects

* small change to test if this is the root of the problem

* reverted changes

* fixing misspelled directory name

* fixing some errors in the script used in the validate-search-line job in go-ci action

* fixed misspelled field in validate_scan_results function

* simplifying code

* using pymarshal to use models that unmarshal json content directly

* fixing errors in results_models pymarshal import

* testing searchLine defined to '-1' hardcoded value

* convert line and searchLine to int

* adding print's for debug purposes

* adding print's for debug purposes

* fixing cases where searchLine is defined to an hardcoded value of -1

* added prints for debug purposes

* debug prints

* debug prints

* debug prints

* changes for debug purposes

* .

* changes

* trying to fix cases with -1 hardcoded on searchLine

* changes

* more changes

* trying type_assert

* trying type_assert

* trying type_assert

* trying type_assert

* trying type_assert

* testing new scenario

* testing test3 case from artur test branch

* testing test3 case from artur test branch

* back to the other scenario

* back to the other scenario again

* used unmarshal_json from pumarshal to unmarshal the json with the results

* testing hardcoded .1 again

* trying case - common_lib.build_search_line([shdfosdhfoisdhf], []),

* reverting changes on dockerfiles

* removed the usage of type_assert to be more permissive about fields not defined on the results file

* changed to see other case output in the actions

* added field queries_failed_to_execute

* changing query searchLine field to test another scenario

* changed to another scenario

* reverting changes made on the query

* changed to test scenario when "searchLine": common_lib.build_search_line(["potatos"], [])

* testing scenario where searchLine is defined to '-1'

* removed unnecessary pymarshal pip instalation

* testing another scenario

* testing searchLine defined to '-1'

* testing searchLine defined to 'potatos'

* reverting query changezs

* reverting changes on query

* reverting changes on docker files

* reverting changes on dockerfiles

* removed \n

* adding debug prints to see the output from variables produced by dorny/path

* added \n

* added echo for debug purposes

* Reverting changes on Dockerfile

* adding print on script

* testing outcome

* using Set Up python step outcome value to define if validate search line in modified queries runs or not

* changing go-jose version

* changing script code to match Codacy best practices

* changing code to comply with the Codacy quality standards

* changing go.mod

* fixing Codacy issues

* changing Go and Git images on Dockerfile

* changing go.mod

* reverting changes on go.mod

* changing go version

* fixing scripts according to Codacy issues

* fixing script to be up to the Codacy quality standards

* fixing Codacy issues

* fixing Codacy issues

* fixing Codacy issues

* fixing D212 in validate_search_line.py file

* reverting changes to fix D212

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>

* Change to use actions role (Checkmarx#8040)

* Change to use actions role

* Update run-projects.yaml

* ci(secrets): use aws oidc (Checkmarx#8041)

* ci: fix aws secrets

* ci: fix permissions

* ci: remove audience

* ci: test gh token

* ci: use sha

* fix(query): fix FP results on "IAM policy allows for data exfiltration" CloudFormation and Terraform queries (Checkmarx#8030)

* Added missing check/associated tests to cloudFormation and Terraform iam_policy data exfiltration queries

---------

Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>

* [StepSecurity] Apply security best practices (Checkmarx#8060)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* [StepSecurity] Apply security best practices (Checkmarx#8063)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* chore: remove Dependabot configuration

* Remove old SBOM (Checkmarx#8071)

Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>

* fix(vulnerabilities): update dockerfile and fix trivy vulnerabilities (Checkmarx#8076)

* update: dockerfile and fix vulnerabilities

* update: dockerfile with arguments before both FROM for universal scope

* update: vulnerable packages and dockerfile images

* ci: trigger

* fix: dockerfile deprecation notice for LegacyKeyValueFormat

* bug(security): fix security vulnerability findings (Checkmarx#8084)

* fix insecure temp file

* fix insecure temp file perms

* add path traversal sanitation

* add path traversal sanitization

* add path traversal sanitization tests

* add path traversal sanitization e2e tests

* add path traversal sanitization e2e tests

* fix lint issues

* fix secrets inspector possible resource exhaustion

* fix secrets line detection for end of document specific case

* bump deps and actions versions

* bump deps and actions versions

* [StepSecurity] Apply security best practices (Checkmarx#8060)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* [StepSecurity] Apply security best practices (Checkmarx#8063)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>

* chore: remove Dependabot configuration

* Remove old SBOM (Checkmarx#8071)

Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>

* fix(vulnerabilities): update dockerfile and fix trivy vulnerabilities (Checkmarx#8076)

* update: dockerfile and fix vulnerabilities

* update: dockerfile with arguments before both FROM for universal scope

* update: vulnerable packages and dockerfile images

* ci: trigger

* fix: dockerfile deprecation notice for LegacyKeyValueFormat

---------

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Co-authored-by: Ohad Israeli <243351248+cx-ohad-israeli@users.noreply.github.com>
Co-authored-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>

* Requested change

* update images and pacakges for vulnerabilities

* bump compress to 1.18.7

---------

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Signed-off-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
Co-authored-by: Ricardo Jesus <219317970+cx-ricardo-jesus@users.noreply.github.com>
Co-authored-by: Artur Ribeiro <153724638+cx-artur-ribeiro@users.noreply.github.com>
Co-authored-by: Bruno Silva <73999905+cx-bruno-silva@users.noreply.github.com>
Co-authored-by: Rui Araújo Gomes <110477212+cx-rui-araujo@users.noreply.github.com>
Co-authored-by: João Reigota <74597872+cx-joao-reigota@users.noreply.github.com>
Co-authored-by: Rafael Carvalho <153817659+cx-rafael-carvalho@users.noreply.github.com>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Co-authored-by: Ohad Israeli <243351248+cx-ohad-israeli@users.noreply.github.com>
Co-authored-by: Yevgeny Kuznetsov <yevgeny.kuznetsov@checkmarx.com>
Co-authored-by: Miguel da Silva <100352574+cx-miguel-dasilva@users.noreply.github.com>
Co-authored-by: cx-miguel-silva <100352574+cx-miguel-silva@users.noreply.github.com>
…/cicd (Checkmarx#8089)

* added coverage for github.event.comment.user.login in issue_comment event type

* added coverage for some pattern in push events in Run Block Injection query

* added coverage for some pattern in push events in Script Block Injection query

* added pattern that was only covered by the run block injection query
…Checkmarx#8087)

* added new case on the negative tests

* updating query

---------

Co-authored-by: Alon Rosenhek <80337069+cx-alon-rosenhek@users.noreply.github.com>
…kerfile (Checkmarx#8090)

* solved specific FP for RUN commands with multiple flags with arguments

* added new test samples

* covered the scenarios where there is a RUN command with a list
@cx-andre-pereira
cx-andre-pereira force-pushed the Dockerfile_queries_fix_for_case_insensitivity branch from aaadece to d10f038 Compare July 28, 2026 17:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community Community contribution docker Docker query dockerfile query New query feature workflows-approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants