Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Error running bandit - bandit_runner.exe not found #58

Open
piraces opened this issue Jun 3, 2023 · 2 comments
Open

Error running bandit - bandit_runner.exe not found #58

piraces opened this issue Jun 3, 2023 · 2 comments

Comments

@piraces
Copy link

piraces commented Jun 3, 2023

Hello. I'm setting up the action in multiple repositories and all of them fails in the same step, while trying to execute bandit.

Logs:

Error:      Error running tool 2 of 5: bandit
Error:      Error running bandit job: 1 of 1
Error:      ToolLauncherNotFoundException: Could not successfully find the D:\a\_msdo\packages\nuget\Microsoft.Guardian.BanditRedist_windows_amd64.1.6.3.1\tools\bandit_runner.exe tool launcher. Please ensure any dependent frameworks are installed.
Error:      Win32Exception: An error occurred trying to start process 'D:\a\_msdo\packages\nuget\Microsoft.Guardian.BanditRedist_windows_amd64.1.6.3.1\tools\bandit_runner.exe' with working directory 'D:\a\AzureGoat\AzureGoat'. The filename or extension is too long.
Error:      BreakException: Guardian detected one or more breaking results.
Error: Error: The process 'D:\a\_msdo\versions\microsoft.security.devops.cli\0.163.0\tools\guardian.cmd' failed with exit code 1

The action run resides in: https://github.com/rpiraces-plain/AzureGoat/actions/runs/5164467559/jobs/9303379837

How can I fix this? I have set up anything wrong?

Edit:
Works perfectly fine with ubuntu-latest runner... seems it only fails with windows-latest runner.

@JiandongJiang
Copy link
Contributor

From the logs, it looks like that the Bandit issue was caused by the length of the Bandit command line too long ("The filename or extension is too long." in the log) due to the command length restriction on Windows. As a workaround, to shorten the length of the Bandit command line on Windows, you can follow the wiki at "https://github.com/microsoft/security-devops-action/wiki#bandit-options" to configure the Target argument so as for Bandit to scan fewer files and see if it will resolve the issue. If you need Bandit to scan more files, you can follow the same wiki to create a *.gdnconfig file to run Bandit multiple times on different targets. Meanwhile, we will seek if there could be a way to better handle it.

@piraces
Copy link
Author

piraces commented Jun 6, 2023

Thank you for your response @JiandongJiang ! I will try to do that 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants