Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add exclusions for openid4java and seasar frameworks #7417

Merged
merged 1 commit into from
Aug 13, 2024

Conversation

manuel-alvarez-alvarez
Copy link
Member

@manuel-alvarez-alvarez manuel-alvarez-alvarez commented Aug 13, 2024

What Does This Do

Adds IAST exclusions for org.openid4java and org.seasar

Motivation

We've seen issues in one customer related to classes that get instrumented by IAST, since it provides no value it's better to exclude them.

Additional Notes

Contributor Checklist

Jira ticket: [PROJ-IDENT]

@manuel-alvarez-alvarez manuel-alvarez-alvarez added the comp: asm iast Application Security Management (IAST) label Aug 13, 2024
@manuel-alvarez-alvarez manuel-alvarez-alvarez requested a review from a team as a code owner August 13, 2024 07:39
@pr-commenter
Copy link

pr-commenter bot commented Aug 13, 2024

Benchmarks

Startup

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
git_branch master malvarez/iast-exclude-openid4java
git_commit_date 1723512885 1723534052
git_commit_sha 594de2e ca5db11
release_version 1.39.0-SNAPSHOT~594de2e160 1.39.0-SNAPSHOT~ca5db118ab
See matching parameters
Baseline Candidate
application insecure-bank insecure-bank
ci_job_date 1723536548 1723536548
ci_job_id 602836511 602836511
ci_pipeline_id 41561983 41561983
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
module Agent Agent
parent None None
variant iast iast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 48 metrics, 15 unstable metrics.

Startup time reports for petclinic
gantt
    title petclinic - global startup overhead: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160

    dateFormat X
    axisFormat %s
section tracing
Agent [baseline] (1.053 s) : 0, 1052568
Total [baseline] (10.385 s) : 0, 10385130
Agent [candidate] (1.046 s) : 0, 1046233
Total [candidate] (10.375 s) : 0, 10374653
section appsec
Agent [baseline] (1.168 s) : 0, 1167836
Total [baseline] (10.488 s) : 0, 10488412
Agent [candidate] (1.169 s) : 0, 1169073
Total [candidate] (10.467 s) : 0, 10466588
section iast
Agent [baseline] (1.176 s) : 0, 1175520
Total [baseline] (10.812 s) : 0, 10812083
Agent [candidate] (1.174 s) : 0, 1174027
Total [candidate] (10.781 s) : 0, 10781327
section profiling
Agent [baseline] (1.244 s) : 0, 1244054
Total [baseline] (10.636 s) : 0, 10636380
Agent [candidate] (1.244 s) : 0, 1244088
Total [candidate] (10.589 s) : 0, 10589490
Loading
  • baseline results
Module Variant Duration Δ tracing
Agent tracing 1.053 s -
Agent appsec 1.168 s 115.269 ms (11.0%)
Agent iast 1.176 s 122.953 ms (11.7%)
Agent profiling 1.244 s 191.486 ms (18.2%)
Total tracing 10.385 s -
Total appsec 10.488 s 103.282 ms (1.0%)
Total iast 10.812 s 426.953 ms (4.1%)
Total profiling 10.636 s 251.25 ms (2.4%)
  • candidate results
Module Variant Duration Δ tracing
Agent tracing 1.046 s -
Agent appsec 1.169 s 122.84 ms (11.7%)
Agent iast 1.174 s 127.794 ms (12.2%)
Agent profiling 1.244 s 197.855 ms (18.9%)
Total tracing 10.375 s -
Total appsec 10.467 s 91.935 ms (0.9%)
Total iast 10.781 s 406.674 ms (3.9%)
Total profiling 10.589 s 214.837 ms (2.1%)
gantt
    title petclinic - break down per module: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160

    dateFormat X
    axisFormat %s
section tracing
BytebuddyAgent [baseline] (671.953 ms) : 0, 671953
BytebuddyAgent [candidate] (667.336 ms) : 0, 667336
GlobalTracer [baseline] (307.673 ms) : 0, 307673
GlobalTracer [candidate] (306.424 ms) : 0, 306424
AppSec [baseline] (51.222 ms) : 0, 51222
AppSec [candidate] (50.875 ms) : 0, 50875
Remote Config [baseline] (695.265 µs) : 0, 695
Remote Config [candidate] (687.48 µs) : 0, 687
Telemetry [baseline] (7.521 ms) : 0, 7521
Telemetry [candidate] (7.485 ms) : 0, 7485
section appsec
BytebuddyAgent [baseline] (677.25 ms) : 0, 677250
BytebuddyAgent [candidate] (677.801 ms) : 0, 677801
GlobalTracer [baseline] (299.731 ms) : 0, 299731
GlobalTracer [candidate] (300.441 ms) : 0, 300441
AppSec [baseline] (156.637 ms) : 0, 156637
AppSec [candidate] (156.608 ms) : 0, 156608
Remote Config [baseline] (598.7 µs) : 0, 599
Remote Config [candidate] (607.365 µs) : 0, 607
Telemetry [baseline] (8.72 ms) : 0, 8720
Telemetry [candidate] (9.013 ms) : 0, 9013
IAST [baseline] (22.867 ms) : 0, 22867
IAST [candidate] (22.2 ms) : 0, 22200
section iast
BytebuddyAgent [baseline] (781.674 ms) : 0, 781674
BytebuddyAgent [candidate] (780.484 ms) : 0, 780484
GlobalTracer [baseline] (296.08 ms) : 0, 296080
GlobalTracer [candidate] (295.777 ms) : 0, 295777
AppSec [baseline] (53.346 ms) : 0, 53346
AppSec [candidate] (51.533 ms) : 0, 51533
Remote Config [baseline] (577.527 µs) : 0, 578
Remote Config [candidate] (619.151 µs) : 0, 619
Telemetry [baseline] (7.107 ms) : 0, 7107
Telemetry [candidate] (7.947 ms) : 0, 7947
IAST [baseline] (23.286 ms) : 0, 23286
IAST [candidate] (24.214 ms) : 0, 24214
section profiling
BytebuddyAgent [baseline] (662.475 ms) : 0, 662475
BytebuddyAgent [candidate] (663.15 ms) : 0, 663150
GlobalTracer [baseline] (389.896 ms) : 0, 389896
GlobalTracer [candidate] (389.749 ms) : 0, 389749
AppSec [baseline] (52.1 ms) : 0, 52100
AppSec [candidate] (52.01 ms) : 0, 52010
Remote Config [baseline] (687.111 µs) : 0, 687
Remote Config [candidate] (684.877 µs) : 0, 685
Telemetry [baseline] (7.362 ms) : 0, 7362
Telemetry [candidate] (7.389 ms) : 0, 7389
ProfilingAgent [baseline] (94.36 ms) : 0, 94360
ProfilingAgent [candidate] (93.976 ms) : 0, 93976
Profiling [baseline] (94.384 ms) : 0, 94384
Profiling [candidate] (94.0 ms) : 0, 94000
Loading
Startup time reports for insecure-bank
gantt
    title insecure-bank - global startup overhead: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160

    dateFormat X
    axisFormat %s
section tracing
Agent [baseline] (1.046 s) : 0, 1046418
Total [baseline] (8.471 s) : 0, 8470708
Agent [candidate] (1.043 s) : 0, 1043211
Total [candidate] (8.505 s) : 0, 8504827
section iast
Agent [baseline] (1.174 s) : 0, 1173507
Total [baseline] (8.938 s) : 0, 8937733
Agent [candidate] (1.186 s) : 0, 1186108
Total [candidate] (9.014 s) : 0, 9013919
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.174 s) : 0, 1174346
Total [baseline] (8.948 s) : 0, 8947862
Agent [candidate] (1.174 s) : 0, 1174095
Total [candidate] (8.981 s) : 0, 8981402
section iast_TELEMETRY_OFF
Agent [baseline] (1.173 s) : 0, 1172872
Total [baseline] (8.979 s) : 0, 8978956
Agent [candidate] (1.172 s) : 0, 1171866
Total [candidate] (8.963 s) : 0, 8962785
Loading
  • baseline results
Module Variant Duration Δ tracing
Agent tracing 1.046 s -
Agent iast 1.174 s 127.089 ms (12.1%)
Agent iast_HARDCODED_SECRET_DISABLED 1.174 s 127.928 ms (12.2%)
Agent iast_TELEMETRY_OFF 1.173 s 126.454 ms (12.1%)
Total tracing 8.471 s -
Total iast 8.938 s 467.025 ms (5.5%)
Total iast_HARDCODED_SECRET_DISABLED 8.948 s 477.154 ms (5.6%)
Total iast_TELEMETRY_OFF 8.979 s 508.248 ms (6.0%)
  • candidate results
Module Variant Duration Δ tracing
Agent tracing 1.043 s -
Agent iast 1.186 s 142.897 ms (13.7%)
Agent iast_HARDCODED_SECRET_DISABLED 1.174 s 130.884 ms (12.5%)
Agent iast_TELEMETRY_OFF 1.172 s 128.655 ms (12.3%)
Total tracing 8.505 s -
Total iast 9.014 s 509.092 ms (6.0%)
Total iast_HARDCODED_SECRET_DISABLED 8.981 s 476.575 ms (5.6%)
Total iast_TELEMETRY_OFF 8.963 s 457.958 ms (5.4%)
gantt
    title insecure-bank - break down per module: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160

    dateFormat X
    axisFormat %s
section tracing
BytebuddyAgent [baseline] (667.941 ms) : 0, 667941
BytebuddyAgent [candidate] (665.096 ms) : 0, 665096
GlobalTracer [baseline] (305.971 ms) : 0, 305971
GlobalTracer [candidate] (305.621 ms) : 0, 305621
AppSec [baseline] (50.913 ms) : 0, 50913
AppSec [candidate] (50.894 ms) : 0, 50894
Remote Config [baseline] (688.286 µs) : 0, 688
Remote Config [candidate] (684.503 µs) : 0, 685
Telemetry [baseline] (7.516 ms) : 0, 7516
Telemetry [candidate] (7.521 ms) : 0, 7521
section iast
BytebuddyAgent [baseline] (780.799 ms) : 0, 780799
BytebuddyAgent [candidate] (789.347 ms) : 0, 789347
GlobalTracer [baseline] (295.354 ms) : 0, 295354
GlobalTracer [candidate] (298.34 ms) : 0, 298340
AppSec [baseline] (54.052 ms) : 0, 54052
AppSec [candidate] (52.82 ms) : 0, 52820
IAST [baseline] (22.239 ms) : 0, 22239
IAST [candidate] (24.24 ms) : 0, 24240
Remote Config [baseline] (587.348 µs) : 0, 587
Remote Config [candidate] (589.283 µs) : 0, 589
Telemetry [baseline] (7.045 ms) : 0, 7045
Telemetry [candidate] (7.196 ms) : 0, 7196
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (781.572 ms) : 0, 781572
BytebuddyAgent [candidate] (780.686 ms) : 0, 780686
GlobalTracer [baseline] (296.633 ms) : 0, 296633
GlobalTracer [candidate] (296.612 ms) : 0, 296612
AppSec [baseline] (51.728 ms) : 0, 51728
AppSec [candidate] (51.092 ms) : 0, 51092
IAST [baseline] (22.336 ms) : 0, 22336
IAST [candidate] (22.775 ms) : 0, 22775
Remote Config [baseline] (579.328 µs) : 0, 579
Remote Config [candidate] (595.333 µs) : 0, 595
Telemetry [baseline] (7.982 ms) : 0, 7982
Telemetry [candidate] (8.809 ms) : 0, 8809
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (778.957 ms) : 0, 778957
BytebuddyAgent [candidate] (778.259 ms) : 0, 778259
GlobalTracer [baseline] (296.238 ms) : 0, 296238
GlobalTracer [candidate] (296.699 ms) : 0, 296699
AppSec [baseline] (50.781 ms) : 0, 50781
AppSec [candidate] (52.283 ms) : 0, 52283
IAST [baseline] (25.683 ms) : 0, 25683
IAST [candidate] (23.571 ms) : 0, 23571
Remote Config [baseline] (627.162 µs) : 0, 627
Remote Config [candidate] (595.404 µs) : 0, 595
Telemetry [baseline] (7.09 ms) : 0, 7090
Telemetry [candidate] (6.957 ms) : 0, 6957
Loading

Load

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
end_time 2024-08-13T07:39:55 2024-08-13T07:46:42
git_branch master malvarez/iast-exclude-openid4java
git_commit_date 1723512885 1723534052
git_commit_sha 594de2e ca5db11
release_version 1.39.0-SNAPSHOT~594de2e160 1.39.0-SNAPSHOT~ca5db118ab
start_time 2024-08-13T07:39:42 2024-08-13T07:46:29
See matching parameters
Baseline Candidate
application insecure-bank insecure-bank
ci_job_date 1723535546 1723535546
ci_job_id 602836512 602836512
ci_pipeline_id 41561983 41561983
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
variant iast iast

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 17 unstable metrics.

Request duration reports for petclinic
gantt
    title petclinic - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
    dateFormat X
    axisFormat %s
section baseline
no_agent (1.339 ms) : 1320, 1358
.   : milestone, 1339,
appsec (1.714 ms) : 1690, 1738
.   : milestone, 1714,
appsec_no_iast (1.697 ms) : 1672, 1722
.   : milestone, 1697,
iast (1.476 ms) : 1454, 1498
.   : milestone, 1476,
profiling (1.48 ms) : 1456, 1505
.   : milestone, 1480,
tracing (1.469 ms) : 1445, 1493
.   : milestone, 1469,
section candidate
no_agent (1.34 ms) : 1321, 1360
.   : milestone, 1340,
appsec (1.714 ms) : 1691, 1738
.   : milestone, 1714,
appsec_no_iast (1.723 ms) : 1699, 1747
.   : milestone, 1723,
iast (1.483 ms) : 1460, 1506
.   : milestone, 1483,
profiling (1.508 ms) : 1482, 1534
.   : milestone, 1508,
tracing (1.459 ms) : 1434, 1484
.   : milestone, 1459,
Loading
  • baseline results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 1.339 ms [1.32 ms, 1.358 ms] -
appsec 1.714 ms [1.69 ms, 1.738 ms] 374.848 µs (28.0%)
appsec_no_iast 1.697 ms [1.672 ms, 1.722 ms] 358.23 µs (26.8%)
iast 1.476 ms [1.454 ms, 1.498 ms] 136.969 µs (10.2%)
profiling 1.48 ms [1.456 ms, 1.505 ms] 141.402 µs (10.6%)
tracing 1.469 ms [1.445 ms, 1.493 ms] 130.187 µs (9.7%)
  • candidate results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 1.34 ms [1.321 ms, 1.36 ms] -
appsec 1.714 ms [1.691 ms, 1.738 ms] 374.138 µs (27.9%)
appsec_no_iast 1.723 ms [1.699 ms, 1.747 ms] 382.526 µs (28.5%)
iast 1.483 ms [1.46 ms, 1.506 ms] 142.771 µs (10.7%)
profiling 1.508 ms [1.482 ms, 1.534 ms] 167.964 µs (12.5%)
tracing 1.459 ms [1.434 ms, 1.484 ms] 118.515 µs (8.8%)
Request duration reports for insecure-bank
gantt
    title insecure-bank - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
    dateFormat X
    axisFormat %s
section baseline
no_agent (359.226 µs) : 339, 379
.   : milestone, 359,
iast (473.582 µs) : 452, 495
.   : milestone, 474,
iast_FULL (550.188 µs) : 528, 573
.   : milestone, 550,
iast_GLOBAL (501.06 µs) : 478, 524
.   : milestone, 501,
iast_HARDCODED_SECRET_DISABLED (469.156 µs) : 448, 490
.   : milestone, 469,
iast_INACTIVE (457.979 µs) : 436, 480
.   : milestone, 458,
iast_TELEMETRY_OFF (461.395 µs) : 441, 482
.   : milestone, 461,
tracing (435.267 µs) : 415, 456
.   : milestone, 435,
section candidate
no_agent (369.839 µs) : 350, 389
.   : milestone, 370,
iast (473.406 µs) : 452, 495
.   : milestone, 473,
iast_FULL (543.868 µs) : 522, 566
.   : milestone, 544,
iast_GLOBAL (506.115 µs) : 484, 529
.   : milestone, 506,
iast_HARDCODED_SECRET_DISABLED (473.739 µs) : 453, 495
.   : milestone, 474,
iast_INACTIVE (452.0 µs) : 430, 474
.   : milestone, 452,
iast_TELEMETRY_OFF (471.288 µs) : 450, 493
.   : milestone, 471,
tracing (440.242 µs) : 419, 462
.   : milestone, 440,
Loading
  • baseline results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 359.226 µs [339.489 µs, 378.963 µs] -
iast 473.582 µs [452.421 µs, 494.744 µs] 114.356 µs (31.8%)
iast_FULL 550.188 µs [527.846 µs, 572.529 µs] 190.962 µs (53.2%)
iast_GLOBAL 501.06 µs [478.057 µs, 524.062 µs] 141.834 µs (39.5%)
iast_HARDCODED_SECRET_DISABLED 469.156 µs [448.328 µs, 489.985 µs] 109.931 µs (30.6%)
iast_INACTIVE 457.979 µs [435.671 µs, 480.287 µs] 98.753 µs (27.5%)
iast_TELEMETRY_OFF 461.395 µs [440.653 µs, 482.136 µs] 102.169 µs (28.4%)
tracing 435.267 µs [414.619 µs, 455.915 µs] 76.041 µs (21.2%)
  • candidate results
Variant Request duration [CI 0.99] Δ no_agent
no_agent 369.839 µs [350.179 µs, 389.498 µs] -
iast 473.406 µs [452.069 µs, 494.742 µs] 103.567 µs (28.0%)
iast_FULL 543.868 µs [521.59 µs, 566.145 µs] 174.029 µs (47.1%)
iast_GLOBAL 506.115 µs [483.544 µs, 528.685 µs] 136.276 µs (36.8%)
iast_HARDCODED_SECRET_DISABLED 473.739 µs [452.74 µs, 494.738 µs] 103.9 µs (28.1%)
iast_INACTIVE 452.0 µs [429.589 µs, 474.411 µs] 82.161 µs (22.2%)
iast_TELEMETRY_OFF 471.288 µs [449.831 µs, 492.744 µs] 101.449 µs (27.4%)
tracing 440.242 µs [418.768 µs, 461.715 µs] 70.403 µs (19.0%)

Dacapo

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
git_branch master malvarez/iast-exclude-openid4java
git_commit_date 1723512885 1723534052
git_commit_sha 594de2e ca5db11
release_version 1.39.0-SNAPSHOT~594de2e160 1.39.0-SNAPSHOT~ca5db118ab
See matching parameters
Baseline Candidate
application biojava biojava
ci_job_date 1723536041 1723536041
ci_job_id 602836513 602836513
ci_pipeline_id 41561983 41561983
cpu_model Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8259CL CPU @ 2.50GHz
variant appsec appsec

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics.

Execution time for biojava
gantt
    title biojava - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
    dateFormat X
    axisFormat %s
section baseline
no_agent (15.471 s) : 15471000, 15471000
.   : milestone, 15471000,
appsec (15.082 s) : 15082000, 15082000
.   : milestone, 15082000,
iast (18.81 s) : 18810000, 18810000
.   : milestone, 18810000,
iast_GLOBAL (17.929 s) : 17929000, 17929000
.   : milestone, 17929000,
profiling (15.276 s) : 15276000, 15276000
.   : milestone, 15276000,
tracing (15.014 s) : 15014000, 15014000
.   : milestone, 15014000,
section candidate
no_agent (15.224 s) : 15224000, 15224000
.   : milestone, 15224000,
appsec (15.106 s) : 15106000, 15106000
.   : milestone, 15106000,
iast (18.905 s) : 18905000, 18905000
.   : milestone, 18905000,
iast_GLOBAL (17.818 s) : 17818000, 17818000
.   : milestone, 17818000,
profiling (15.24 s) : 15240000, 15240000
.   : milestone, 15240000,
tracing (15.161 s) : 15161000, 15161000
.   : milestone, 15161000,
Loading
  • baseline results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 15.471 s [15.471 s, 15.471 s] -
appsec 15.082 s [15.082 s, 15.082 s] -389.0 ms (-2.5%)
iast 18.81 s [18.81 s, 18.81 s] 3.339 s (21.6%)
iast_GLOBAL 17.929 s [17.929 s, 17.929 s] 2.458 s (15.9%)
profiling 15.276 s [15.276 s, 15.276 s] -195.0 ms (-1.3%)
tracing 15.014 s [15.014 s, 15.014 s] -457.0 ms (-3.0%)
  • candidate results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 15.224 s [15.224 s, 15.224 s] -
appsec 15.106 s [15.106 s, 15.106 s] -118.0 ms (-0.8%)
iast 18.905 s [18.905 s, 18.905 s] 3.681 s (24.2%)
iast_GLOBAL 17.818 s [17.818 s, 17.818 s] 2.594 s (17.0%)
profiling 15.24 s [15.24 s, 15.24 s] 16.0 ms (0.1%)
tracing 15.161 s [15.161 s, 15.161 s] -63.0 ms (-0.4%)
Execution time for tomcat
gantt
    title tomcat - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
    dateFormat X
    axisFormat %s
section baseline
no_agent (1.467 ms) : 1455, 1478
.   : milestone, 1467,
appsec (2.217 ms) : 2182, 2252
.   : milestone, 2217,
iast (1.956 ms) : 1914, 1997
.   : milestone, 1956,
iast_GLOBAL (2.017 ms) : 1975, 2060
.   : milestone, 2017,
profiling (1.852 ms) : 1818, 1885
.   : milestone, 1852,
tracing (1.854 ms) : 1821, 1886
.   : milestone, 1854,
section candidate
no_agent (1.466 ms) : 1454, 1477
.   : milestone, 1466,
appsec (2.22 ms) : 2186, 2255
.   : milestone, 2220,
iast (1.978 ms) : 1935, 2020
.   : milestone, 1978,
iast_GLOBAL (2.019 ms) : 1976, 2062
.   : milestone, 2019,
profiling (1.86 ms) : 1826, 1894
.   : milestone, 1860,
tracing (1.847 ms) : 1814, 1880
.   : milestone, 1847,
Loading
  • baseline results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 1.467 ms [1.455 ms, 1.478 ms] -
appsec 2.217 ms [2.182 ms, 2.252 ms] 749.901 µs (51.1%)
iast 1.956 ms [1.914 ms, 1.997 ms] 488.829 µs (33.3%)
iast_GLOBAL 2.017 ms [1.975 ms, 2.06 ms] 550.554 µs (37.5%)
profiling 1.852 ms [1.818 ms, 1.885 ms] 384.803 µs (26.2%)
tracing 1.854 ms [1.821 ms, 1.886 ms] 386.899 µs (26.4%)
  • candidate results
Variant Execution Time [CI 0.99] Δ no_agent
no_agent 1.466 ms [1.454 ms, 1.477 ms] -
appsec 2.22 ms [2.186 ms, 2.255 ms] 754.642 µs (51.5%)
iast 1.978 ms [1.935 ms, 2.02 ms] 511.763 µs (34.9%)
iast_GLOBAL 2.019 ms [1.976 ms, 2.062 ms] 553.365 µs (37.8%)
profiling 1.86 ms [1.826 ms, 1.894 ms] 394.161 µs (26.9%)
tracing 1.847 ms [1.814 ms, 1.88 ms] 381.296 µs (26.0%)

@manuel-alvarez-alvarez manuel-alvarez-alvarez merged commit 8b3304e into master Aug 13, 2024
82 checks passed
@manuel-alvarez-alvarez manuel-alvarez-alvarez deleted the malvarez/iast-exclude-openid4java branch August 13, 2024 12:37
@github-actions github-actions bot added this to the 1.39.0 milestone Aug 13, 2024
smola pushed a commit that referenced this pull request Aug 13, 2024
smola added a commit that referenced this pull request Aug 14, 2024
(cherry picked from commit 8b3304e)

Co-authored-by: Manuel Álvarez Álvarez <manuel-alvarez-alvarez@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
comp: asm iast Application Security Management (IAST) type: bug
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants