Skip to content

Cannot generate YAML #2

@cosad3s

Description

@cosad3s

Following the README, I have an error when the command is executed:

docker run -e "IS_IMPLEMENTED_WHEN_EVIDENCE=true" -v $(pwd)/data/custom:/var/www/html/src/assets/YAML/custom -v /tmp/generated:/var/www/html/src/assets/YAML/generated wurstbrot/dsomm-yaml-generation

Result:

Unable to find image 'wurstbrot/dsomm-yaml-generation:latest' locally
latest: Pulling from wurstbrot/dsomm-yaml-generation
ccaf924377f9: Pull complete 
abe1a413c0f2: Pull complete 
b4c5cfbe408c: Pull complete 
a0d4f187046e: Pull complete 
74d9e2a2c4e5: Pull complete 
83b1cb2c9fc3: Pull complete 
6cca6aaf7815: Pull complete 
fea811f66c2a: Pull complete 
46e56028e4f0: Pull complete 
e7b54089e01d: Pull complete 
4fb01fad4e03: Pull complete 
9b4f5e556be4: Pull complete 
e6dd2fee4113: Pull complete 
00caf65af3af: Pull complete 
4f4fb700ef54: Pull complete 
bee8c6c1364d: Pull complete 
7d5fe52635a9: Pull complete 
05b66219bdb3: Pull complete 
1178fe2e048e: Pull complete 
613cfdaf9ca1: Pull complete 
35de6ac0651b: Pull complete 
11b3db3b982c: Pull complete 
Digest: sha256:481a47c0918cfa94fa018882a1b057440a6073176993fb173de253d090a9867a
Status: Downloaded newer image for wurstbrot/dsomm-yaml-generation:latest
Reading src/assets/YAML/default/BuildAndDeployment/Build.yaml
Reading src/assets/YAML/default/BuildAndDeployment/Deployment.yaml
Reading src/assets/YAML/default/BuildAndDeployment/PatchManagement.yaml
Reading src/assets/YAML/default/BuildAndDeployment/_meta.yaml
Reading src/assets/YAML/default/CultureAndOrganization/Design.yaml
Reading src/assets/YAML/default/CultureAndOrganization/EducationAndGuidance.yaml
Reading src/assets/YAML/default/CultureAndOrganization/Process.yaml
Reading src/assets/YAML/default/CultureAndOrganization/_meta.yaml
Reading src/assets/YAML/default/Implementation/ApplicationHardening.yaml
Reading src/assets/YAML/default/Implementation/DevelopmentAndSourceControl.yaml
Reading src/assets/YAML/default/Implementation/InfrastructureHardening.yaml
Reading src/assets/YAML/default/Implementation/_meta.yaml
Reading src/assets/YAML/default/InformationGathering/Logging.yaml
Reading src/assets/YAML/default/InformationGathering/Monitoring.yaml
Reading src/assets/YAML/default/InformationGathering/TestKPI.yaml
Reading src/assets/YAML/default/InformationGathering/_meta.yaml
Reading src/assets/YAML/default/TestAndVerification/ApplicationTests.yaml
Reading src/assets/YAML/default/TestAndVerification/Consolidation.yaml
Reading src/assets/YAML/default/TestAndVerification/DynamicDepthForApplications.yaml
Reading src/assets/YAML/default/TestAndVerification/DynamicDepthForInfrastructure.yaml
Reading src/assets/YAML/default/TestAndVerification/StaticDepthForApplications.yaml
Reading src/assets/YAML/default/TestAndVerification/StaticDepthForInfrastructure.yaml
Reading src/assets/YAML/default/TestAndVerification/Test-Intensity.yaml
Reading src/assets/YAML/default/TestAndVerification/_meta.yaml
Reading custom src/assets/YAML/custom/definition/definition.yaml
Reading custom src/assets/YAML/custom/implementations/applicationA.yaml
In file src/assets/YAML/custom/implementations/applicationA.yaml, including src/assets/YAML/custom/implementations/platformZ.yaml for team A
File to include src/assets/YAML/custom/implementations/platformZ.yaml# setting teamsImplemented first time for team A# adding team to teamsImplemented for team A# setting teamsImplemented first time for team A# adding team to teamsImplemented for team AReading custom src/assets/YAML/custom/implementations/applicationB.yaml
Reading custom src/assets/YAML/custom/implementations/platformZ.yaml
unsetting Build
unsetting Patch Management
unsetting Design
unsetting Process
unsetting Application Hardening
unsetting Development and Source Control
unsetting Infrastructure Hardening
unsetting Logging
unsetting Monitoring
unsetting Test KPI
unsetting Dynamic depth for applications
unsetting Dynamic depth for infrastructure
unsetting Static depth for infrastructure
unsetting Test Intensity
unsetting Patch Management
unsetting Design
unsetting Process
unsetting Application Hardening
unsetting Development and Source Control
unsetting Infrastructure Hardening
unsetting Logging
unsetting Monitoring
unsetting Test KPI
unsetting Dynamic depth for applications
unsetting Dynamic depth for infrastructure
unsetting Static depth for infrastructure
unsetting Test Intensity
unsetting Patch Management
unsetting Design
unsetting Process
unsetting Application Hardening
unsetting Development and Source Control
unsetting Infrastructure Hardening
unsetting Logging
unsetting Monitoring
unsetting Test KPI
unsetting Dynamic depth for applications
unsetting Dynamic depth for infrastructure
unsetting Static depth for infrastructure
unsetting Test Intensity
unsetting Static depth for infrastructure
unsetting Test Intensity
unsetting Implementation
unsetting Information Gathering

INFO: Reference never used: implementations: argocd
INFO: Reference never used: implementations: signing-of-commits-protection
INFO: Reference never used: implementations: signing-of-commits
INFO: Reference never used: implementations: chaosmonkey
INFO: Reference never used: implementations: ci-cd-tools
INFO: Reference never used: implementations: apimaturity
INFO: Reference never used: implementations: container-technology
INFO: Reference never used: implementations: cwe-838
INFO: Reference never used: implementations: docker-content-trust
INFO: Reference never used: implementations: in-toto
INFO: Reference never used: implementations: a-complete-backup-of
INFO: Reference never used: implementations: a-point-in-time-reco
INFO: Reference never used: implementations: docker
INFO: Reference never used: implementations: webserver
INFO: Reference never used: implementations: rolling-update
INFO: Reference never used: implementations: kubernetes-admission
INFO: Reference never used: implementations: dependabot
INFO: Reference never used: implementations: renovate
INFO: Reference never used: implementations: jenkins
INFO: Reference never used: implementations: maven
INFO: Reference never used: implementations: sample-concept-1
INFO: Reference never used: implementations: distroless
INFO: Reference never used: implementations: fedora-coreos
INFO: Reference never used: implementations: distroless-usage
INFO: Reference never used: implementations: threat-modeling-play
INFO: Reference never used: implementations: owasp-samm
INFO: Reference never used: implementations: whiteboard
INFO: Reference never used: implementations: miro-or-any-other-c
INFO: Reference never used: implementations: draw-io
INFO: Reference never used: implementations: threagile
INFO: Reference never used: implementations: don-t-forget-evil-user-stories
INFO: Reference never used: implementations: libyear
INFO: Reference never used: implementations: owasp-security-champ
INFO: Reference never used: implementations: build-it-break-it-fi
INFO: Reference never used: implementations: motivate-people
INFO: Reference never used: implementations: owasp-top-10-maturit
INFO: Reference never used: implementations: involve-security-sme
INFO: Reference never used: implementations: example-all-docker
INFO: Reference never used: implementations: owasp-asvs
INFO: Reference never used: implementations: owasp-masvs
INFO: Reference never used: implementations: cis-kubernetes-benchmark
INFO: Reference never used: implementations: cis-docker-benchmark
INFO: Reference never used: implementations: for-example-for-cont
INFO: Reference never used: implementations: attack-matrix-cloud
INFO: Reference never used: implementations: attack-matrix-containers
INFO: Reference never used: implementations: attack-matrix-kubern
INFO: Reference never used: implementations: istio
INFO: Reference never used: implementations: bridges
INFO: Reference never used: implementations: firewalls
INFO: Reference never used: implementations: open-policy-agent
INFO: Reference never used: implementations: gitops
INFO: Reference never used: implementations: ansible
INFO: Reference never used: implementations: chef
INFO: Reference never used: implementations: puppet
INFO: Reference never used: implementations: jenkinsfile
INFO: Reference never used: implementations: seccomp
INFO: Reference never used: implementations: strace
INFO: Reference never used: implementations: remove-direct-access
INFO: Reference never used: implementations: directory-service
INFO: Reference never used: implementations: plugins
INFO: Reference never used: implementations: yubikey
INFO: Reference never used: implementations: sms
INFO: Reference never used: implementations: totp
INFO: Reference never used: implementations: http-basic-authentic
INFO: Reference never used: implementations: vpn
INFO: Reference never used: implementations: for-applications-ch
INFO: Reference never used: implementations: managing-secrets
INFO: Reference never used: implementations: crypto
INFO: Reference never used: implementations: authentication
INFO: Reference never used: implementations: rsyslog
INFO: Reference never used: implementations: logstash
INFO: Reference never used: implementations: fluentd
INFO: Reference never used: implementations: bash
INFO: Reference never used: implementations: owasp-logging-cheats
INFO: Reference never used: implementations: owasp-dom-xss-cheats
INFO: Reference never used: implementations: owasp-parameterization-cheats
INFO: Reference never used: implementations: elk-stack
INFO: Reference never used: implementations: prometheus
INFO: Reference never used: implementations: collected
INFO: Reference never used: implementations: SecObserve
INFO: Reference never used: implementations: sast
INFO: Reference never used: implementations: dast
INFO: Reference never used: implementations: logparser-jenkins-pl
INFO: Reference never used: implementations: owasp-code-pulse
INFO: Reference never used: implementations: ajax-spider
INFO: Reference never used: implementations: curl
INFO: Reference never used: implementations: openapi
INFO: Reference never used: implementations: owasp-zap
INFO: Reference never used: implementations: arachni
INFO: Reference never used: implementations: zest
INFO: Reference never used: implementations: owasp-securecodebox
INFO: Reference never used: implementations: kube-hunter
INFO: Reference never used: implementations: openvas
INFO: Reference never used: implementations: htc-hydra
INFO: Reference never used: implementations: netassert
INFO: Reference never used: implementations: nmap
INFO: Reference never used: implementations: owasp-amass
INFO: Reference never used: implementations: k8spurger
INFO: Reference never used: implementations: pmd
INFO: Reference never used: implementations: eslint
INFO: Reference never used: implementations: findsecuritybugs
INFO: Reference never used: implementations: jsprime
INFO: Reference never used: implementations: bdd-mobile-security
INFO: Reference never used: implementations: sigmahq
INFO: Reference never used: implementations: dive-to-inspect-a-co
INFO: Reference never used: implementations: clusterscanner
INFO: Reference never used: implementations: dockerfile-with-hado
INFO: Reference never used: implementations: deployment-with-kube
INFO: Reference never used: implementations: kubesec
INFO: Reference never used: implementations: anchore-io
INFO: Reference never used: implementations: clair
INFO: Reference never used: implementations: openscap
INFO: Reference never used: implementations: vuls
INFO: Reference never used: implementations: kube-bench
INFO: Reference never used: implementations: trufflehog
INFO: Reference never used: implementations: go-pillage-registrie
INFO: Reference never used: implementations: syft
INFO: Reference never used: implementations: grype
INFO: Reference never used: implementations: registries-like-quay
INFO: Reference never used: implementations: dockerfilelint
INFO: Reference never used: implementations: threat-matrix-for-storage
INFO: Reference never used: implementations: defend-the-core-kubernetes
INFO: Reference never used: implementations: business-friendly-vulnerability-metrics
INFO: Reference never used: implementations: kubescape
INFO: Reference never used: implementations: azuredevops
INFO: Reference never used: implementations: github-policies
INFO: Reference never used: implementations: sonarqube-lint
INFO: Reference never used: implementations: stylecop
INFO: Reference never used: implementations: fortify-vscode-extension
INFO: Reference never used: implementations: appscan-vscode-extension
INFO: Reference never used: implementations: checkmarx-vscode-extension
INFO: Reference never used: implementations: pre-commit-microsoft
INFO: Reference never used: implementations: pre-commit-synopsis
INFO: Reference never used: implementations: hashicorp-vault
INFO: Reference never used: implementations: stoplight-spectral
INFO: Reference never used: implementations: api-oas-checker
INFO: Reference never used: implementations: coveragepy
INFO: Reference never used: implementations: github-super-linter
INFO: Reference never used: implementations: schemathesis
INFO: Reference never used: implementations: martin-feature-toggles
INFO: Reference never used: implementations: defectdojo-client
INFO: Reference never used: implementations: falco
INFO: Reference never used: implementations: sammancoaching
INFO: Reference never used: implementations: terraform
INFO: Reference never used: implementations: packj
INFO: Reference never used: implementations: api-myths
INFO: Reference never used: implementations: backstage
INFO: Reference never used: implementations: image-metadata-collector
INFO: Reference never used: implementations: jira
INFO: Reference never used: implementations: epss
INFO: Reference never used: implementations: cisa-kev
INFO: Reference never used: implementations: owasp-secure-headers
INFO: Reference never used: implementations: citrusframework
INFO: Reference never used: implementations: signing-of-containers
INFO: Reference never used: implementations: immutable-images


Found 5 errors:
ERROR: DependsOn non-existing activity uuid: f6f7737f-25a9-4317-8de2-09bf59f29b5b  (in activity: 'Defined deployment process')
ERROR: DependsOn non-existing activity uuid: 066084c6-1135-4635-9cc5-9e75c7c5459f  (in activity: 'Defined deployment process')
ERROR: DependsOn non-existing activity: 'Smoke Test' (in activity: Blue/Green Deployment)
ERROR: DependsOn non-existing activity: 'Defined build process' (in activity: Software Composition Analysis (server side))
ERROR: DependsOn non-existing activity uuid: 2a44b708-734f-4463-b0cb-86dc46344b2f  (in activity: 'Software Composition Analysis (server side)')
Please fix the errors

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions