Splunk Dev

How to update a Splunk® Add-on Builder built app or add-on?

sloshburch
Splunk Employee
Splunk Employee

Some of my apps are failing AppInspect's check_for_vulnerable_javascript_library_usage check but I didn't include any javascript. I did built the apps with the Splunk Add-on Builder and I see some javascript that was packaged as a result.

I understand that this is resolved in the newest version of Splunk® Add-on Builder. How do I update my app to be built by this latest version of Splunk Add-on Builder, thereby resolving these issues.

Labels (2)
0 Karma
1 Solution

sloshburch
Splunk Employee
Splunk Employee

Yes! Version 4.1.0 Release Notes show that these items were fixed in 4.1.0!

The way to update your app is a bit nuanced. You'll need to do the following. 

Important: Pay attention to the specific instructions for each of the below linked documentation. For example, in step 3, the documentation details the way to use the "Package and Validate" tab of Add-on Builder, NOT the "Export" link on the first page, and NOT the package that Add-on Builder saves in $SPLUNK_HOME/etc/apps. So please pay attention to the specific instructions of each link to correctly update the app build.

  1. Export the app from any Add-on Builder
  2. Import the app into Add-on Builder v4.1.0 or newer
  3. Download the app packaged from Add-on Builder v4.1.0 or newer. The resulting app package that you download will have the fix!

You can validated by running the old app package against AppInspect with the `cloud` tag, then run the fixed app package against AppInspect with the `cloud`. See Send requests using the Splunk AppInspect collection for Postman  on splunk>dev for more guidance.

View solution in original post

sloshburch
Splunk Employee
Splunk Employee

Yes! Version 4.1.0 Release Notes show that these items were fixed in 4.1.0!

The way to update your app is a bit nuanced. You'll need to do the following. 

Important: Pay attention to the specific instructions for each of the below linked documentation. For example, in step 3, the documentation details the way to use the "Package and Validate" tab of Add-on Builder, NOT the "Export" link on the first page, and NOT the package that Add-on Builder saves in $SPLUNK_HOME/etc/apps. So please pay attention to the specific instructions of each link to correctly update the app build.

  1. Export the app from any Add-on Builder
  2. Import the app into Add-on Builder v4.1.0 or newer
  3. Download the app packaged from Add-on Builder v4.1.0 or newer. The resulting app package that you download will have the fix!

You can validated by running the old app package against AppInspect with the `cloud` tag, then run the fixed app package against AppInspect with the `cloud`. See Send requests using the Splunk AppInspect collection for Postman  on splunk>dev for more guidance.

mikedgibson
New Member

I inherited the maintenance of an app that was built with a version of add-on builder that is triggering this warning. Unfortunately, I do not have access to an export of this app from add-on builder. Is there a way for me to make this change without an export then import?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...