Skip to content

Update checkmarx-ast-cli to 2.3.65 - #223

Merged
cx-atish-jadhav merged 4 commits into
mainfrom
feature/update_cli_2.3.65
Sep 18, 2026
Merged

cx-atish-jadhav merged 4 commits into
mainfrom
feature/update_cli_2.3.65

Conversation

@cx-atish-jadhav

Copy link
Copy Markdown

Updated the bundled Checkmarx AST CLI version from 2.3.60 to 2.3.65 and refreshed the platform checksum files for Windows, macOS, and Linux. Also bumped the package version to 1.0.41 to align the release metadata.

Updated the bundled Checkmarx AST CLI version from 2.3.60 to 2.3.65 and refreshed the platform checksum files for Windows, macOS, and Linux. Also bumped the package version to 1.0.41 to align the release metadata.
@cx-atish-jadhav
cx-atish-jadhav requested a review from a team September 18, 2026 07:32
@cx-atish-jadhav cx-atish-jadhav self-assigned this Sep 18, 2026
@stepsecurity-app

stepsecurity-app Bot commented Sep 18, 2026

Copy link
Copy Markdown

Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.ECHO_LIBRARIES_ACCESS_KEY at line 37
  • secrets.CX_CLIENT_ID at line 72
  • secrets.CX_CLIENT_SECRET at line 73
  • secrets.CX_BASE_URI at line 74
  • secrets.CX_BASE_AUTH_URI at line 75
  • secrets.CX_TENANT at line 76
  • secrets.CX_APIKEY at line 77

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-atish-jadhav) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

Extract getScanAndResult helper in PredicateTest to centralize logic for locating a completed scan and its SAST result. Add null-safe checks, use strict equality, and provide a fallback scanShow lookup when no scan is found to reduce flakiness. Update the test to use the helper and keep assertions for triageShow/triageUpdate. Improves readability and robustness of the test.
@cx-atish-jadhav
cx-atish-jadhav merged commit 84a81aa into main Sep 18, 2026
8 of 9 checks passed
@cx-atish-jadhav
cx-atish-jadhav deleted the feature/update_cli_2.3.65 branch September 18, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants