CRIT
SEC084
[SEC084] JS: require() with non-literal: require(<variable>) loads arbitrary modules — eq…
components/camel-cxf/camel-cxf-common/s…:64
CRIT
SEC001
[SEC001] Hardcoded Password: Hardcoded password found in source code.
components/camel-amqp/src/main/java/org…:121
HIGH
MINED108
[MINED108] `self.check_image_versions` used but never assigned in __init__: Method `run_c…
.github/actions/check-container-upgrade…:966
HIGH
MINED108
[MINED108] `self.parse_properties_file` used but never assigned in __init__: Method `run_…
.github/actions/check-container-upgrade…:949
HIGH
MINED108
[MINED108] `self.find_container_properties_files` used but never assigned in __init__: Me…
.github/actions/check-container-upgrade…:932
HIGH
MINED108
[MINED108] `self._is_prerelease` used but never assigned in __init__: Method `check_image…
.github/actions/check-container-upgrade…:903
HIGH
MINED108
[MINED108] `self.parse_container_reference` used but never assigned in __init__: Method `…
.github/actions/check-container-upgrade…:773
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:554
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:554
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:524
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:524
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:494
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:494
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:464
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:464
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:430
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:430
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:399
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:399
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:358
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:358
HIGH
MINED108
[MINED108] `self.timeout` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:320
HIGH
MINED108
[MINED108] `self.session` used but never assigned in __init__: Method `get_available_vers…
.github/actions/check-container-upgrade…:320
HIGH
MINED108
[MINED108] `self._version_pattern` used but never assigned in __init__: Method `is_versio…
.github/actions/check-container-upgrade…:241
HIGH
MINED108
[MINED108] `self.full_name` used but never assigned in __init__: Method `full_image` of c…
.github/actions/check-container-upgrade…:228
HIGH
MINED108
[MINED108] `self._version_pattern` used but never assigned in __init__: Method `__post_in…
.github/actions/check-container-upgrade…:215
HIGH
SEC111
[SEC111] Django mark_safe / |safe filter on user data: Django's `mark_safe()` and `|safe`…
components/camel-google/camel-google-ma…:96
HIGH
SEC113
[SEC113] SSH host-key verification disabled (MITM): Accepting any SSH host key on first c…
components/camel-ftp/src/main/java/org/…:43
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
components/camel-docker/src/main/java/o…:63
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
components/camel-docker/src/main/java/o…:73
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
components/camel-as2/camel-as2-api/src/…:85
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
components/camel-as2/camel-as2-api/src/…:23
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
components/camel-as2/camel-as2-api/src/…:42
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
components/camel-ai/camel-djl/src/main/…:97
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
components/camel-activemq6/src/main/jav…:254
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
components/camel-activemq/src/main/java…:254
HIGH
SEC024
[SEC024] XML External Entity (XXE) — Java parser default: Java XML parsers accept externa…
components/camel-flatpack/src/main/java…:76
HIGH
SEC024
[SEC024] XML External Entity (XXE) — Java parser default: Java XML parsers accept externa…
components/camel-cm-sms/src/main/java/o…:91
HIGH
SEC024
[SEC024] XML External Entity (XXE) — Java parser default: Java XML parsers accept externa…
catalog/camel-route-parser/src/main/jav…:107
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
catalog/camel-catalog-maven/src/main/ja…:29
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
catalog/camel-catalog-maven/src/main/ja…:211
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
catalog/camel-catalog-maven/src/main/ja…:112
HIGH
MINED134
[MINED134] Binary file `.mvn/wrapper/maven-wrapper.jar` committed in source repo: `.mvn/w…
.mvn/wrapper/maven-wrapper.jar:1
HIGH
MINED134
[MINED134] Binary file `dsl/camel-jbang/camel-jbang-core/src/main/resources/maven-wrapper…
dsl/camel-jbang/camel-jbang-core/src/ma…:1
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/pr-labeler.yml:63
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/pr-labeler.yml:40
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v7.0.1`: `uses: actio…
.github/workflows/check-container-versi…:370
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v6`: `uses: actions/setu…
.github/workflows/check-container-versi…:51
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/check-container-versi…:46
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/pr-id.yml:36
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/sonar-scan.yml:157
HIGH
MINED115
[MINED115] Action `actions/cache` pinned to mutable ref `@v5`: `uses: actions/cache@v5` r…
.github/workflows/sonar-scan.yml:127
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/sonar-scan.yml:107
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/sonar-scan.yml:60
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/pr-commenter.yml:72
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/pr-commenter.yml:63
HIGH
MINED115
[MINED115] Action `actions/github-script` pinned to mutable ref `@v9`: `uses: actions/git…
.github/workflows/pr-commenter.yml:40
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v7.0.1`: `uses: actio…
.github/workflows/security-scan.yml:47
HIGH
MINED115
[MINED115] Action `actions/setup-java` pinned to mutable ref `@v5`: `uses: actions/setup-…
.github/workflows/security-scan.yml:39
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/security-scan.yml:35
HIGH
MINED118
[MINED118] Dockerfile FROM `registry.access.redhat.com/ubi9/openjdk-21-runtime:1.24` not …
dsl/camel-jbang/camel-jbang-core/src/ma…:35
HIGH
MINED118
[MINED118] Dockerfile FROM `quay.io/quarkus/ubi9-quarkus-micro-image:2.0` not pinned by d…
dsl/camel-jbang/camel-jbang-core/src/ma…:39
HIGH
MINED118
[MINED118] Dockerfile FROM `registry.access.redhat.com/ubi9/ubi-minimal:9.7` not pinned b…
dsl/camel-jbang/camel-jbang-core/src/ma…:36
HIGH
MINED118
[MINED118] Dockerfile FROM `eclipse-temurin:21-jdk` not pinned by digest: `FROM eclipse-t…
dsl/camel-jbang/camel-jbang-container/D…:17
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
.github/actions/check-container-upgrade…:917
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
.github/actions/check-container-upgrade…:823
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
.github/actions/check-container-upgrade…:1173
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
components/camel-ocsf/src/main/script/g…:667
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
components/camel-ocsf/src/main/script/g…:586
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
components/camel-ocsf/src/main/script/g…:504
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
components/camel-ocsf/src/main/script/g…:442
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
components/camel-docker/src/main/java/o…:63
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
components/camel-docker/src/main/java/o…:73
MED
COMP001
[COMP001] High cognitive complexity: Function `jackson_format` has cognitive complexity 2…
.github/actions/check-container-upgrade…:33
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DKR015
Docker build context is very large
.dockerignore
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
catalog/camel-catalog/src/generated/res…:4
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
catalog/camel-catalog/src/generated/res…:27
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
catalog/camel-catalog/src/generated/res…:35
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
catalog/camel-catalog/src/generated/res…:36
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
catalog/camel-catalog/src/generated/res…:32
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
catalog/camel-catalog/src/generated/res…:28
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
catalog/camel-report-maven-plugin/src/m…:180
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
catalog/camel-report-maven-plugin/src/m…:74
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
catalog/camel-csimple-maven-plugin/src/…:223
LOW
COMP001
[COMP001] High cognitive complexity: Function `handle` has cognitive complexity 8 (SonarS…
components/camel-ai/camel-huggingface/s…:26
LOW
AIC003
Duplicated implementation block across source files
components/camel-activemq6/src/main/jav…:10
LOW
AIC003
Duplicated implementation block across source files
components/camel-activemq6/src/main/jav…:22
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:170
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:81
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:69
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:46
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:29
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:22
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:82
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:47
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:30
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:23
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:62
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:38
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:37
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:42
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:12
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:28
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:10
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:98
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:74
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:45
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:48
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:116
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:214
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:198
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-route-parser/src/main/jav…:454
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-report-maven-plugin/src/m…:22
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-report-maven-plugin/src/m…:31
LOW
AIC003
Duplicated implementation block across source files
catalog/camel-report-maven-plugin/src/m…:23
LOW
AIC007
Generated build artifact directory is present at repository root
coverage:1
INFO
MINED053
[MINED053] Placeholder Default Username: [email protected] / [email protected] / admin/admin…
components/camel-box/camel-box-api/src/…:150
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
components/camel-bonita/src/main/java/o…:34
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
catalog/camel-route-parser/src/main/jav…:99
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
catalog/camel-route-parser/src/main/jav…:39