Description
While uploading the artifact the following message appears:
ARTIFACT PROCESSING MESSAGES
Exception: No valid analysis result was found. Please verify the validity of the result file.
Info: The following exceptions have been approved for processing by userx
The version of the external metadata file "ExternalMetadata/externalmetadata.xml" is more recent in the scan than on the server. The external metadata file in the scan
will be ignored.
Scan Removed: SCA Analysis was performed in Quick Scan mode. Issues were not parsed.
Comment: allowed
Approval Date: 05/01/2024 PM
Resolution
1). Please check the following regarding artifacts approvals:
Note: If a scan artifact requires approval based on analysis result processing rules, it must be approved before Fortify Software Security Center can process it. For information, see Approving Analysis Results for an Application Version.
Reference:
Uploading Scan Artifacts
https://www.microfocus.com/documentation/fortify-software-security-center/2320/SSC_Help_23.2.0/index.htm#SSC_UG/Upload_Arts.htm?Highlight=processing%20rules
2). Also review profile settings:
Ignore SCA quick scan results and SCA speed dial results performed with a setting of less than four:
Blocks the processing of Fortify Static Code Analyzer scans done in quick can mode, which searches for high‑confidence, high‑severity issues. This rule also prevents the upload of speed dial analysis results performed at a level of less than four.
Reference:
Setting Analysis Results Processing Rules for Application Versions
https://www.microfocus.com/documentation/fortify-software-security-center/2320/SSC_Help_23.2.0/index.htm#SSC_UG/Setting_Proc_Rules.htm
When you upload artifacts, there are processing rules applied that control what kind of results are allowed and what kind of results are not. Very likely you have set "Ignore SCA quick scan"
You can see these settings on the Profile for an application version
It's not recommended to have mix quick scan results with full scan results, ideally different scan levels should be on different application versions.