SecurityUpload reports
Upload errors
Each error an upload can return, what it means and what to do.
Error messages
| Error | Meaning | What to do |
|---|---|---|
| Your plan allows N report uploads per pipeline run, and this run already has N. | The run reached its limit. | Upload fewer reports per run, or upgrade. |
| Your plan allows N report uploads per commit, and at already has N. | The commit reached its limit. | Combine reports, or upgrade. |
| Your plan allows N report uploads per commit. already has N uploads without a commit SHA today (UTC). | The daily limit for uploads without a commit. | Send the commit SHA, or wait for the next UTC day. |
| Too many report uploads for your organization this hour (limit N). Try again after HH:00 UTC. | The hourly safety limit. | Wait until the time given. |
| The file is larger than your plan allows (N MB). | The file is over your plan's size limit. | Split the report, or upgrade. |
| The file is not valid JSON. | The file is not JSON, or not UTF-8. | Export the report as JSON. |
| XML reports are not supported. Export the report as JSON (for example CycloneDX JSON or SARIF). | The file is XML. | Export JSON instead. |
| SPDX tag-value files are not supported. Export SPDX as JSON. | The SPDX file is tag-value. | Export SPDX JSON. |
| The report is nested too deeply to read (more than 64 levels). | The JSON is too deep. | Check that a scanner produced the file. |
| The report has too many values to read. | The JSON has more than 5 million values. | Split the report. |
| The file looks like X, not Y. | The you gave does not match the file. | Use , or the right format. |
| The file is not a SARIF, CycloneDX or SPDX report. | Prodgator does not recognize the JSON. | Run the scanner with SARIF output. See Set up a scanner. |
| Grype JSON reports are not supported. ... Run Grype with -o sarif and upload that file. | The file is Grype's own JSON, or you sent . | Run . |
| Trivy JSON reports are not supported. ... Run Trivy with --format sarif and upload that file. | The file is Trivy's own JSON, or you sent . | Run (or ). |
| exists on GitHub and GitLab. Send provider (github, gitlab or bitbucket) to say which repository this is for. | More than one of your providers has a repository with this name. | Send (or pick it on the Security page). |
| The uploaded file does not match its size or checksum. | The PUT file differs from what you declared. | Create the upload again with the right size and SHA-256. |