lo UNKNOWN 127.0.0.1/8 ::1/128 db: database age 2.3 days; UpdatedAt=2026-09-08T19:09:56.811508+00:00 java-db: database age 2.0 days; UpdatedAt=2026-09-09T01:11:59.619689+00:00 ○ │╲ │ ○ ○ ░ ░ gitleaks 3:42AM INF scanned ~45 bytes (45 bytes) in 1.14ms 3:42AM INF no leaks found 2026-09-11T03:42:20+02:00 INFO [vuln] Vulnerability scanning is enabled 2026-09-11T03:42:20+02:00 INFO [misconfig] Misconfiguration scanning is enabled 2026-09-11T03:42:20+02:00 INFO [checks-client] No downloadable checks were loaded as --skip-check-update is enabled, loading from existing cache... 2026-09-11T03:42:21+02:00 INFO Number of language-specific files num=1 2026-09-11T03:42:21+02:00 INFO [pip] Detecting vulnerabilities... 2026-09-11T03:42:21+02:00 INFO Detected config files num=1 2026-09-11T03:42:21+02:00 INFO [vuln] Vulnerability scanning is enabled 2026-09-11T03:42:21+02:00 INFO Number of language-specific files num=1 2026-09-11T03:42:21+02:00 INFO [pip] Detecting vulnerabilities... ○ │╲ │ ○ ○ ░ ░ gitleaks 3:42AM INF scanned ~58 bytes (58 bytes) in 4.12ms 3:42AM WRN leaks found: 1 Private key written to cosign.key Public key written to cosign.pub Using payload from: artifact.txt Signing artifact... Wrote bundle to file artifact.sigstore.json WARNING: Skipping tlog verification is an insecure practice that lacks transparency and auditability verification for the blob. Verified OK WARNING: Skipping tlog verification is an insecure practice that lacks transparency and auditability verification for the blob. Error: failed to verify signature: could not verify message: invalid signature when validating ASN.1 encoded signature error during command execution: failed to verify signature: could not verify message: invalid signature when validating ASN.1 encoded signature PASS: vulnerable dependency blocked, SBOM generated, signature verified, tampering rejected. Test files: /tmp/devsecops-smoke.YAWdyv7u [0000] WARN no explicit name and version provided for directory source, deriving artifact ID from the given path (which is not ideal) [0000] ERROR discovered vulnerabilities at or above the severity threshold [0000] WARN no explicit name and version provided for directory source, deriving artifact ID from the given path (which is not ideal) [0000] ERROR database does not exist PASS: offline secrets/Trivy/signatures/Syft/Grype; clean fixture passes; missing DB fails. Test evidence: /tmp/my-devsecops-test.r2TpgqWd