ProdgatorDocs
SecurityUpload reports

Upload errors

Each error an upload can return, what it means and what to do.

Error messages

ErrorMeaningWhat to do
Your plan allows N report uploads per pipeline run, and this run already has N.The run reached its limit.Upload fewer reports per run, or upgrade.
Your plan allows N report uploads per commit, and at already has N.The commit reached its limit.Combine reports, or upgrade.
Your plan allows N report uploads per commit. already has N uploads without a commit SHA today (UTC).The daily limit for uploads without a commit.Send the commit SHA, or wait for the next UTC day.
Too many report uploads for your organization this hour (limit N). Try again after HH:00 UTC.The hourly safety limit.Wait until the time given.
The file is larger than your plan allows (N MB).The file is over your plan's size limit.Split the report, or upgrade.
The file is not valid JSON.The file is not JSON, or not UTF-8.Export the report as JSON.
XML reports are not supported. Export the report as JSON (for example CycloneDX JSON or SARIF).The file is XML.Export JSON instead.
SPDX tag-value files are not supported. Export SPDX as JSON.The SPDX file is tag-value.Export SPDX JSON.
The report is nested too deeply to read (more than 64 levels).The JSON is too deep.Check that a scanner produced the file.
The report has too many values to read.The JSON has more than 5 million values.Split the report.
The file looks like X, not Y.The you gave does not match the file.Use , or the right format.
The file is not a SARIF, CycloneDX or SPDX report.Prodgator does not recognize the JSON.Run the scanner with SARIF output. See Set up a scanner.
Grype JSON reports are not supported. ... Run Grype with -o sarif and upload that file.The file is Grype's own JSON, or you sent .Run .
Trivy JSON reports are not supported. ... Run Trivy with --format sarif and upload that file.The file is Trivy's own JSON, or you sent .Run (or ).
exists on GitHub and GitLab. Send provider (github, gitlab or bitbucket) to say which repository this is for.More than one of your providers has a repository with this name.Send (or pick it on the Security page).
The uploaded file does not match its size or checksum.The PUT file differs from what you declared.Create the upload again with the right size and SHA-256.

On this page