Failing tests for splitting vulnerabilities into host and container scopes
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@ -677,6 +677,7 @@ mod finding_tests {
|
||||
fixed_version: None,
|
||||
title: "t".into(),
|
||||
url: "u".into(),
|
||||
source: "debian".into(),
|
||||
},
|
||||
status: FindingStatus::Open,
|
||||
first_seen: Utc::now(),
|
||||
@ -751,6 +752,33 @@ mod finding_tests {
|
||||
.unwrap_err(),
|
||||
DomainError::NotFound
|
||||
);
|
||||
|
||||
let host = repo
|
||||
.list(&FindingFilter {
|
||||
target_kind: Some(TargetKind::Os),
|
||||
include_fixed: true,
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
host.iter()
|
||||
.map(|f| f.raw.cve_id.as_str())
|
||||
.collect::<Vec<_>>(),
|
||||
vec!["CVE-A", "CVE-B"]
|
||||
);
|
||||
let images = repo
|
||||
.list(&FindingFilter {
|
||||
target_kind: Some(TargetKind::Image),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(images.len(), 1);
|
||||
assert_eq!(
|
||||
images[0].raw.source, "debian",
|
||||
"source survives the roundtrip"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@ -276,6 +276,24 @@ mod tests {
|
||||
"Vulnerabilities": [{"VulnerabilityID": "GHSA-1", "PkgName": "stdlib", "InstalledVersion": "1.21.5", "Severity": "WEIRD"}]}
|
||||
]}"#;
|
||||
|
||||
#[test]
|
||||
fn keeps_the_trivy_package_type_as_the_finding_source() {
|
||||
let f = parse_trivy_json(SAMPLE).unwrap();
|
||||
let ssl = f.iter().find(|x| x.package == "openssl").unwrap();
|
||||
assert_eq!(ssl.source, "debian", "os package");
|
||||
let go = f.iter().find(|x| x.cve_id == "GHSA-1").unwrap();
|
||||
assert_eq!(go.source, "gobinary", "application binary on the host");
|
||||
// unknown type falls back to an empty source rather than failing
|
||||
assert_eq!(
|
||||
parse_trivy_json(
|
||||
r#"{"Results":[{"Target":"t","Vulnerabilities":[{"VulnerabilityID":"X"}]}]}"#
|
||||
)
|
||||
.unwrap()[0]
|
||||
.source,
|
||||
""
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_results_merges_targets_and_dedups() {
|
||||
let f = parse_trivy_json(SAMPLE).unwrap();
|
||||
|
||||
Reference in New Issue
Block a user