Failing tests for splitting vulnerabilities into host and container scopes
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@ -277,3 +277,89 @@ async fn list_summary_and_status_changes() {
|
||||
.unwrap();
|
||||
assert_eq!(ack.len(), 1);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn findings_are_separated_into_host_and_container_scopes() {
|
||||
let scanner = FakeScanner::default()
|
||||
.with(
|
||||
"os",
|
||||
Ok(vec![
|
||||
raw("CVE-1", "openssl", "3.0.1", Severity::Critical, None),
|
||||
raw("CVE-2", "bash", "5.2", Severity::Low, None),
|
||||
]),
|
||||
)
|
||||
.with(
|
||||
GITEA,
|
||||
Ok(vec![raw("CVE-3", "git", "2.39", Severity::High, None)]),
|
||||
)
|
||||
.with(
|
||||
PG,
|
||||
Ok(vec![raw("CVE-4", "libssl3", "3.0", Severity::Medium, None)]),
|
||||
);
|
||||
let (_f, svc) = fixture(scanner);
|
||||
svc.scan(&VecLog::default()).await.unwrap();
|
||||
|
||||
let host = svc
|
||||
.list(FindingFilter {
|
||||
target_kind: Some(TargetKind::Os),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
host.iter()
|
||||
.map(|f| f.raw.cve_id.as_str())
|
||||
.collect::<Vec<_>>(),
|
||||
vec!["CVE-1", "CVE-2"]
|
||||
);
|
||||
let containers = svc
|
||||
.list(FindingFilter {
|
||||
target_kind: Some(TargetKind::Image),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(containers.len(), 2);
|
||||
assert!(containers
|
||||
.iter()
|
||||
.all(|f| f.target_kind == TargetKind::Image));
|
||||
// a scope combines with the other filters
|
||||
let critical_host = svc
|
||||
.list(FindingFilter {
|
||||
target_kind: Some(TargetKind::Os),
|
||||
min_severity: Some(Severity::High),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(critical_host.len(), 1);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn targets_are_reported_with_their_scope_and_open_count() {
|
||||
let scanner = FakeScanner::default()
|
||||
.with(
|
||||
"os",
|
||||
Ok(vec![
|
||||
raw("CVE-1", "a", "1", Severity::High, None),
|
||||
raw("CVE-2", "b", "1", Severity::Low, None),
|
||||
]),
|
||||
)
|
||||
.with(
|
||||
GITEA,
|
||||
Ok(vec![raw("CVE-3", "c", "1", Severity::High, None)]),
|
||||
);
|
||||
let (_f, svc) = fixture(scanner);
|
||||
svc.scan(&VecLog::default()).await.unwrap();
|
||||
|
||||
let targets = svc.targets().await.unwrap();
|
||||
// host first, then images sorted by name
|
||||
assert_eq!(targets[0].kind, TargetKind::Os);
|
||||
assert_eq!(targets[0].target, "os");
|
||||
assert_eq!(targets[0].open, 2);
|
||||
let image = targets.iter().find(|t| t.target == GITEA).unwrap();
|
||||
assert_eq!(image.kind, TargetKind::Image);
|
||||
assert_eq!(image.open, 1);
|
||||
// an image without findings is not listed
|
||||
assert!(targets.iter().all(|t| t.target != PG));
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user