db: database age 2.3 days; UpdatedAt=2026-09-08T19:09:56.811508+00:00 java-db: database age 2.0 days; UpdatedAt=2026-09-09T01:11:59.619689+00:00 ○ │╲ │ ○ ○ ░ ░ gitleaks 1:45AM INF scanned ~45 bytes (45 bytes) in 1.46ms 1:45AM INF no leaks found 2026-09-11T01:45:19Z INFO [vuln] Vulnerability scanning is enabled 2026-09-11T01:45:19Z INFO [misconfig] Misconfiguration scanning is enabled 2026-09-11T01:45:19Z INFO [checks-client] No downloadable checks were loaded as --skip-check-update is enabled, loading from existing cache... 2026-09-11T01:45:20Z WARN [pip] Unable to find python `site-packages` directory. License detection is skipped. err="site-packages directory not found" 2026-09-11T01:45:20Z INFO Number of language-specific files num=1 2026-09-11T01:45:20Z INFO [pip] Detecting vulnerabilities... 2026-09-11T01:45:20Z INFO Detected config files num=1 2026-09-11T01:45:20Z INFO [vuln] Vulnerability scanning is enabled 2026-09-11T01:45:20Z WARN [pip] Unable to find python `site-packages` directory. License detection is skipped. err="site-packages directory not found" 2026-09-11T01:45:20Z INFO Number of language-specific files num=1 2026-09-11T01:45:20Z INFO [pip] Detecting vulnerabilities... ○ │╲ │ ○ ○ ░ ░ gitleaks 1:45AM INF scanned ~58 bytes (58 bytes) in 4.23ms 1:45AM WRN leaks found: 1 Private key written to cosign.key Public key written to cosign.pub Using payload from: artifact.txt Signing artifact... Wrote bundle to file artifact.sigstore.json WARNING: Skipping tlog verification is an insecure practice that lacks transparency and auditability verification for the blob. Verified OK WARNING: Skipping tlog verification is an insecure practice that lacks transparency and auditability verification for the blob. Error: failed to verify signature: could not verify message: invalid signature when validating ASN.1 encoded signature error during command execution: failed to verify signature: could not verify message: invalid signature when validating ASN.1 encoded signature PASS: vulnerable dependency blocked, SBOM generated, signature verified, tampering rejected. Test files: /tmp/devsecops-smoke.g87J2wcW Private key written to cosign.key Public key written to cosign.pub Using payload from: release.sha256 Signing artifact... Wrote bundle to file release.sigstore.json WARNING: Skipping tlog verification is an insecure practice that lacks transparency and auditability verification for the blob. Verified OK app.tar: OK image.cdx.json: OK WARNING: Skipping tlog verification is an insecure practice that lacks transparency and auditability verification for the blob. Verified OK app.tar: FAILED image.cdx.json: OK sha256sum: WARNING: 1 computed checksum did NOT match PASS: container smoke, signing adapter, tampered-release rejection and evidence archive