-
Notifications
You must be signed in to change notification settings - Fork 279
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade to AppSec rules v1.12.0 #7192
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
smola
approved these changes
Jun 14, 2024
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 57 metrics, 14 unstable metrics. Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.063 s) : 0, 1062941
Total [baseline] (10.382 s) : 0, 10381713
Agent [candidate] (1.072 s) : 0, 1071533
Total [candidate] (10.384 s) : 0, 10384303
section appsec
Agent [baseline] (1.183 s) : 0, 1182738
Total [baseline] (10.478 s) : 0, 10478057
Agent [candidate] (1.186 s) : 0, 1185965
Total [candidate] (10.497 s) : 0, 10496616
section iast
Agent [baseline] (1.178 s) : 0, 1178203
Total [baseline] (10.717 s) : 0, 10717352
Agent [candidate] (1.168 s) : 0, 1168236
Total [candidate] (10.628 s) : 0, 10628374
section profiling
Agent [baseline] (1.264 s) : 0, 1264118
Total [baseline] (10.658 s) : 0, 10658468
Agent [candidate] (1.269 s) : 0, 1268712
Total [candidate] (10.664 s) : 0, 10664408
gantt
title petclinic - break down per module: candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (665.672 ms) : 0, 665672
BytebuddyAgent [candidate] (670.722 ms) : 0, 670722
GlobalTracer [baseline] (303.797 ms) : 0, 303797
GlobalTracer [candidate] (307.114 ms) : 0, 307114
AppSec [baseline] (50.582 ms) : 0, 50582
AppSec [candidate] (50.338 ms) : 0, 50338
Logs Intake [baseline] (340.17 µs) : 0, 340
Logs Intake [candidate] (344.541 µs) : 0, 345
Remote Config [baseline] (676.562 µs) : 0, 677
Remote Config [candidate] (685.415 µs) : 0, 685
Telemetry [baseline] (7.582 ms) : 0, 7582
Telemetry [candidate] (7.689 ms) : 0, 7689
section appsec
BytebuddyAgent [baseline] (678.176 ms) : 0, 678176
BytebuddyAgent [candidate] (679.72 ms) : 0, 679720
GlobalTracer [baseline] (297.66 ms) : 0, 297660
GlobalTracer [candidate] (297.995 ms) : 0, 297995
AppSec [baseline] (152.831 ms) : 0, 152831
AppSec [candidate] (153.52 ms) : 0, 153520
Logs Intake [baseline] (337.369 µs) : 0, 337
Logs Intake [candidate] (335.282 µs) : 0, 335
Remote Config [baseline] (646.648 µs) : 0, 647
Remote Config [candidate] (642.241 µs) : 0, 642
Telemetry [baseline] (7.805 ms) : 0, 7805
Telemetry [candidate] (8.196 ms) : 0, 8196
IAST [baseline] (21.606 ms) : 0, 21606
IAST [candidate] (21.891 ms) : 0, 21891
section iast
BytebuddyAgent [baseline] (785.617 ms) : 0, 785617
BytebuddyAgent [candidate] (778.949 ms) : 0, 778949
GlobalTracer [baseline] (295.324 ms) : 0, 295324
GlobalTracer [candidate] (293.489 ms) : 0, 293489
AppSec [baseline] (47.418 ms) : 0, 47418
AppSec [candidate] (46.868 ms) : 0, 46868
Logs Intake [baseline] (298.286 µs) : 0, 298
Logs Intake [candidate] (300.809 µs) : 0, 301
Remote Config [baseline] (568.203 µs) : 0, 568
Remote Config [candidate] (579.643 µs) : 0, 580
Telemetry [baseline] (7.638 ms) : 0, 7638
Telemetry [candidate] (9.245 ms) : 0, 9245
IAST [baseline] (27.955 ms) : 0, 27955
IAST [candidate] (25.539 ms) : 0, 25539
section profiling
ProfilingAgent [baseline] (96.676 ms) : 0, 96676
ProfilingAgent [candidate] (96.268 ms) : 0, 96268
BytebuddyAgent [baseline] (664.251 ms) : 0, 664251
BytebuddyAgent [candidate] (667.066 ms) : 0, 667066
GlobalTracer [baseline] (386.472 ms) : 0, 386472
GlobalTracer [candidate] (388.099 ms) : 0, 388099
AppSec [baseline] (51.255 ms) : 0, 51255
AppSec [candidate] (51.366 ms) : 0, 51366
Logs Intake [baseline] (329.732 µs) : 0, 330
Logs Intake [candidate] (350.925 µs) : 0, 351
Remote Config [baseline] (686.313 µs) : 0, 686
Remote Config [candidate] (708.143 µs) : 0, 708
Telemetry [baseline] (7.328 ms) : 0, 7328
Telemetry [candidate] (7.449 ms) : 0, 7449
Profiling [baseline] (96.701 ms) : 0, 96701
Profiling [candidate] (96.293 ms) : 0, 96293
Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.06 s) : 0, 1060170
Total [baseline] (8.541 s) : 0, 8541207
Agent [candidate] (1.076 s) : 0, 1076380
Total [candidate] (8.583 s) : 0, 8583188
section iast
Agent [baseline] (1.17 s) : 0, 1170306
Total [baseline] (9.029 s) : 0, 9029374
Agent [candidate] (1.168 s) : 0, 1168496
Total [candidate] (8.98 s) : 0, 8980393
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.183 s) : 0, 1183342
Total [baseline] (8.968 s) : 0, 8967872
Agent [candidate] (1.172 s) : 0, 1171652
Total [candidate] (8.966 s) : 0, 8965846
section iast_TELEMETRY_OFF
Agent [baseline] (1.166 s) : 0, 1165717
Total [baseline] (8.978 s) : 0, 8978371
Agent [candidate] (1.166 s) : 0, 1165983
Total [candidate] (8.976 s) : 0, 8976251
gantt
title insecure-bank - break down per module: candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (664.21 ms) : 0, 664210
BytebuddyAgent [candidate] (674.609 ms) : 0, 674609
GlobalTracer [baseline] (302.78 ms) : 0, 302780
GlobalTracer [candidate] (307.807 ms) : 0, 307807
AppSec [baseline] (50.218 ms) : 0, 50218
AppSec [candidate] (50.472 ms) : 0, 50472
Logs Intake [baseline] (332.839 µs) : 0, 333
Logs Intake [candidate] (340.157 µs) : 0, 340
Remote Config [baseline] (668.389 µs) : 0, 668
Remote Config [candidate] (681.834 µs) : 0, 682
Telemetry [baseline] (7.57 ms) : 0, 7570
Telemetry [candidate] (7.603 ms) : 0, 7603
section iast
BytebuddyAgent [baseline] (779.833 ms) : 0, 779833
BytebuddyAgent [candidate] (778.448 ms) : 0, 778448
GlobalTracer [baseline] (293.646 ms) : 0, 293646
GlobalTracer [candidate] (292.808 ms) : 0, 292808
AppSec [baseline] (47.082 ms) : 0, 47082
AppSec [candidate] (46.916 ms) : 0, 46916
IAST [baseline] (27.16 ms) : 0, 27160
IAST [candidate] (26.802 ms) : 0, 26802
Logs Intake [baseline] (313.883 µs) : 0, 314
Logs Intake [candidate] (300.967 µs) : 0, 301
Remote Config [baseline] (580.222 µs) : 0, 580
Remote Config [candidate] (1.316 ms) : 0, 1316
Telemetry [baseline] (8.382 ms) : 0, 8382
Telemetry [candidate] (8.578 ms) : 0, 8578
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (790.306 ms) : 0, 790306
BytebuddyAgent [candidate] (781.313 ms) : 0, 781313
GlobalTracer [baseline] (295.706 ms) : 0, 295706
GlobalTracer [candidate] (293.798 ms) : 0, 293798
AppSec [baseline] (47.237 ms) : 0, 47237
AppSec [candidate] (47.039 ms) : 0, 47039
IAST [baseline] (26.564 ms) : 0, 26564
IAST [candidate] (28.268 ms) : 0, 28268
Logs Intake [baseline] (304.852 µs) : 0, 305
Logs Intake [candidate] (308.294 µs) : 0, 308
Remote Config [baseline] (570.652 µs) : 0, 571
Remote Config [candidate] (581.72 µs) : 0, 582
Telemetry [baseline] (9.118 ms) : 0, 9118
Telemetry [candidate] (6.936 ms) : 0, 6936
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (777.903 ms) : 0, 777903
BytebuddyAgent [candidate] (777.231 ms) : 0, 777231
GlobalTracer [baseline] (293.175 ms) : 0, 293175
GlobalTracer [candidate] (293.398 ms) : 0, 293398
AppSec [baseline] (47.905 ms) : 0, 47905
AppSec [candidate] (48.606 ms) : 0, 48606
IAST [baseline] (24.178 ms) : 0, 24178
IAST [candidate] (24.678 ms) : 0, 24678
Logs Intake [baseline] (294.849 µs) : 0, 295
Logs Intake [candidate] (302.412 µs) : 0, 302
Remote Config [baseline] (566.467 µs) : 0, 566
Remote Config [candidate] (593.62 µs) : 0, 594
Telemetry [baseline] (8.344 ms) : 0, 8344
Telemetry [candidate] (7.794 ms) : 0, 7794
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 16 unstable metrics. Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section baseline
no_agent (379.116 µs) : 359, 400
. : milestone, 379,
iast (477.799 µs) : 457, 499
. : milestone, 478,
iast_FULL (562.606 µs) : 541, 584
. : milestone, 563,
iast_GLOBAL (509.439 µs) : 487, 532
. : milestone, 509,
iast_HARDCODED_SECRET_DISABLED (483.898 µs) : 463, 505
. : milestone, 484,
iast_INACTIVE (453.837 µs) : 433, 475
. : milestone, 454,
iast_TELEMETRY_OFF (477.995 µs) : 457, 499
. : milestone, 478,
tracing (438.55 µs) : 418, 459
. : milestone, 439,
section candidate
no_agent (370.409 µs) : 351, 390
. : milestone, 370,
iast (479.432 µs) : 458, 501
. : milestone, 479,
iast_FULL (552.94 µs) : 532, 574
. : milestone, 553,
iast_GLOBAL (516.342 µs) : 494, 538
. : milestone, 516,
iast_HARDCODED_SECRET_DISABLED (488.794 µs) : 467, 511
. : milestone, 489,
iast_INACTIVE (451.447 µs) : 431, 472
. : milestone, 451,
iast_TELEMETRY_OFF (473.436 µs) : 452, 495
. : milestone, 473,
tracing (443.254 µs) : 422, 465
. : milestone, 443,
Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section baseline
no_agent (1.339 ms) : 1320, 1359
. : milestone, 1339,
appsec (1.715 ms) : 1691, 1738
. : milestone, 1715,
appsec_no_iast (1.695 ms) : 1670, 1721
. : milestone, 1695,
iast (1.482 ms) : 1459, 1504
. : milestone, 1482,
profiling (1.48 ms) : 1455, 1505
. : milestone, 1480,
tracing (1.476 ms) : 1452, 1500
. : milestone, 1476,
section candidate
no_agent (1.349 ms) : 1330, 1368
. : milestone, 1349,
appsec (1.723 ms) : 1699, 1747
. : milestone, 1723,
appsec_no_iast (1.708 ms) : 1684, 1733
. : milestone, 1708,
iast (1.488 ms) : 1466, 1510
. : milestone, 1488,
profiling (1.502 ms) : 1477, 1528
. : milestone, 1502,
tracing (1.462 ms) : 1437, 1486
. : milestone, 1462,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section baseline
no_agent (14.976 s) : 14976000, 14976000
. : milestone, 14976000,
appsec (15.282 s) : 15282000, 15282000
. : milestone, 15282000,
iast (18.929 s) : 18929000, 18929000
. : milestone, 18929000,
iast_GLOBAL (17.821 s) : 17821000, 17821000
. : milestone, 17821000,
profiling (15.12 s) : 15120000, 15120000
. : milestone, 15120000,
tracing (14.922 s) : 14922000, 14922000
. : milestone, 14922000,
section candidate
no_agent (14.91 s) : 14910000, 14910000
. : milestone, 14910000,
appsec (15.148 s) : 15148000, 15148000
. : milestone, 15148000,
iast (18.86 s) : 18860000, 18860000
. : milestone, 18860000,
iast_GLOBAL (17.984 s) : 17984000, 17984000
. : milestone, 17984000,
profiling (15.393 s) : 15393000, 15393000
. : milestone, 15393000,
tracing (15.014 s) : 15014000, 15014000
. : milestone, 15014000,
Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.36.0-SNAPSHOT~677324a135, baseline=1.36.0-SNAPSHOT~fba045085f
dateFormat X
axisFormat %s
section baseline
no_agent (1.455 ms) : 1443, 1466
. : milestone, 1455,
appsec (2.192 ms) : 2158, 2226
. : milestone, 2192,
iast (1.96 ms) : 1919, 2001
. : milestone, 1960,
iast_GLOBAL (1.984 ms) : 1944, 2025
. : milestone, 1984,
profiling (1.845 ms) : 1811, 1879
. : milestone, 1845,
tracing (1.829 ms) : 1797, 1861
. : milestone, 1829,
section candidate
no_agent (1.464 ms) : 1452, 1475
. : milestone, 1464,
appsec (2.195 ms) : 2161, 2229
. : milestone, 2195,
iast (1.956 ms) : 1915, 1996
. : milestone, 1956,
iast_GLOBAL (2.004 ms) : 1962, 2045
. : milestone, 2004,
profiling (1.84 ms) : 1807, 1872
. : milestone, 1840,
tracing (1.817 ms) : 1786, 1849
. : milestone, 1817,
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Does This Do
Upgrade to the latest Application Security rules.
Motivation
The new configuration provides SSRF, LFI and SQLi rules for exploit prevention.
Additional Notes