Failing tests for splitting vulnerabilities into host and container scopes

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 19:38:04 +02:00
parent a146f09935
commit 21098cadf6
8 changed files with 334 additions and 4 deletions

View File

@ -167,3 +167,88 @@ async fn notification_threshold_setting_and_permissions() {
StatusCode::UNAUTHORIZED
);
}
#[tokio::test]
async fn findings_are_scoped_into_host_and_containers() {
let app = test_app_with_admin().await;
let token = common::login(&app, ADMIN, PW).await.access;
run_scan(&app, &token).await;
let host = get(
&app,
"/api/vulnerabilities?scope=host&min_severity=unknown",
Some(&token),
)
.await;
assert_eq!(host.status, StatusCode::OK, "{}", host.json);
let host_list = host.json.as_array().unwrap();
assert!(!host_list.is_empty());
assert!(host_list
.iter()
.all(|f| f["target_kind"] == "os" && f["target"] == "os"));
assert!(
host_list.iter().any(|f| f["source"] == "debian"),
"host findings name their package source"
);
let containers = get(
&app,
"/api/vulnerabilities?scope=container&min_severity=unknown",
Some(&token),
)
.await;
let container_list = containers.json.as_array().unwrap();
assert!(!container_list.is_empty());
assert!(container_list.iter().all(|f| f["target_kind"] == "image"));
assert!(container_list
.iter()
.any(|f| f["target"].as_str().unwrap().contains("gitea")));
let all = get(
&app,
"/api/vulnerabilities?min_severity=unknown",
Some(&token),
)
.await;
assert_eq!(
all.json.as_array().unwrap().len(),
host_list.len() + container_list.len()
);
assert_eq!(
get(&app, "/api/vulnerabilities?scope=nope", Some(&token))
.await
.status,
StatusCode::UNPROCESSABLE_ENTITY
);
// the summary splits the same way
let s = get(&app, "/api/vulnerabilities/summary", Some(&token)).await;
let sum = |v: &serde_json::Value| {
v["critical"].as_u64().unwrap()
+ v["high"].as_u64().unwrap()
+ v["medium"].as_u64().unwrap()
+ v["low"].as_u64().unwrap()
+ v["unknown"].as_u64().unwrap()
};
assert_eq!(sum(&s.json["os"]) as usize, host_list.len());
assert_eq!(sum(&s.json["images"]) as usize, container_list.len());
}
#[tokio::test]
async fn targets_carry_their_scope_and_open_count() {
let app = test_app_with_admin().await;
let token = common::login(&app, ADMIN, PW).await.access;
run_scan(&app, &token).await;
let res = get(&app, "/api/vulnerabilities/targets", Some(&token)).await;
let targets = res.json.as_array().unwrap();
assert_eq!(targets[0]["kind"], "os", "the host comes first");
assert_eq!(targets[0]["target"], "os");
assert!(targets[0]["open"].as_u64().unwrap() >= 3);
let image = targets
.iter()
.find(|t| t["target"].as_str().unwrap().contains("gitea"))
.unwrap();
assert_eq!(image["kind"], "image");
assert!(image["open"].as_u64().unwrap() >= 1);
}

View File

@ -277,3 +277,89 @@ async fn list_summary_and_status_changes() {
.unwrap();
assert_eq!(ack.len(), 1);
}
#[tokio::test]
async fn findings_are_separated_into_host_and_container_scopes() {
let scanner = FakeScanner::default()
.with(
"os",
Ok(vec![
raw("CVE-1", "openssl", "3.0.1", Severity::Critical, None),
raw("CVE-2", "bash", "5.2", Severity::Low, None),
]),
)
.with(
GITEA,
Ok(vec![raw("CVE-3", "git", "2.39", Severity::High, None)]),
)
.with(
PG,
Ok(vec![raw("CVE-4", "libssl3", "3.0", Severity::Medium, None)]),
);
let (_f, svc) = fixture(scanner);
svc.scan(&VecLog::default()).await.unwrap();
let host = svc
.list(FindingFilter {
target_kind: Some(TargetKind::Os),
..Default::default()
})
.await
.unwrap();
assert_eq!(
host.iter()
.map(|f| f.raw.cve_id.as_str())
.collect::<Vec<_>>(),
vec!["CVE-1", "CVE-2"]
);
let containers = svc
.list(FindingFilter {
target_kind: Some(TargetKind::Image),
..Default::default()
})
.await
.unwrap();
assert_eq!(containers.len(), 2);
assert!(containers
.iter()
.all(|f| f.target_kind == TargetKind::Image));
// a scope combines with the other filters
let critical_host = svc
.list(FindingFilter {
target_kind: Some(TargetKind::Os),
min_severity: Some(Severity::High),
..Default::default()
})
.await
.unwrap();
assert_eq!(critical_host.len(), 1);
}
#[tokio::test]
async fn targets_are_reported_with_their_scope_and_open_count() {
let scanner = FakeScanner::default()
.with(
"os",
Ok(vec![
raw("CVE-1", "a", "1", Severity::High, None),
raw("CVE-2", "b", "1", Severity::Low, None),
]),
)
.with(
GITEA,
Ok(vec![raw("CVE-3", "c", "1", Severity::High, None)]),
);
let (_f, svc) = fixture(scanner);
svc.scan(&VecLog::default()).await.unwrap();
let targets = svc.targets().await.unwrap();
// host first, then images sorted by name
assert_eq!(targets[0].kind, TargetKind::Os);
assert_eq!(targets[0].target, "os");
assert_eq!(targets[0].open, 2);
let image = targets.iter().find(|t| t.target == GITEA).unwrap();
assert_eq!(image.kind, TargetKind::Image);
assert_eq!(image.open, 1);
// an image without findings is not listed
assert!(targets.iter().all(|t| t.target != PG));
}

View File

@ -677,6 +677,7 @@ mod finding_tests {
fixed_version: None,
title: "t".into(),
url: "u".into(),
source: "debian".into(),
},
status: FindingStatus::Open,
first_seen: Utc::now(),
@ -751,6 +752,33 @@ mod finding_tests {
.unwrap_err(),
DomainError::NotFound
);
let host = repo
.list(&FindingFilter {
target_kind: Some(TargetKind::Os),
include_fixed: true,
..Default::default()
})
.await
.unwrap();
assert_eq!(
host.iter()
.map(|f| f.raw.cve_id.as_str())
.collect::<Vec<_>>(),
vec!["CVE-A", "CVE-B"]
);
let images = repo
.list(&FindingFilter {
target_kind: Some(TargetKind::Image),
..Default::default()
})
.await
.unwrap();
assert_eq!(images.len(), 1);
assert_eq!(
images[0].raw.source, "debian",
"source survives the roundtrip"
);
}
}

View File

@ -276,6 +276,24 @@ mod tests {
"Vulnerabilities": [{"VulnerabilityID": "GHSA-1", "PkgName": "stdlib", "InstalledVersion": "1.21.5", "Severity": "WEIRD"}]}
]}"#;
#[test]
fn keeps_the_trivy_package_type_as_the_finding_source() {
let f = parse_trivy_json(SAMPLE).unwrap();
let ssl = f.iter().find(|x| x.package == "openssl").unwrap();
assert_eq!(ssl.source, "debian", "os package");
let go = f.iter().find(|x| x.cve_id == "GHSA-1").unwrap();
assert_eq!(go.source, "gobinary", "application binary on the host");
// unknown type falls back to an empty source rather than failing
assert_eq!(
parse_trivy_json(
r#"{"Results":[{"Target":"t","Vulnerabilities":[{"VulnerabilityID":"X"}]}]}"#
)
.unwrap()[0]
.source,
""
);
}
#[test]
fn parses_results_merges_targets_and_dedups() {
let f = parse_trivy_json(SAMPLE).unwrap();