Roll findings up per package and image, expandable to their CVEs
The findings table listed every CVE, which is thousands of rows on a real host. It now shows one row per affected package (host) or image (containers) with its severity split, how many findings it has and how many of them have a fix. Clicking a row loads and shows the CVEs of that group; collapsing keeps them cached. The rollup is a GROUP BY in SQLite behind a new groups endpoint, so the page loads a few dozen rows instead of the full finding list, and the flat list gained a package filter to expand one group. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@ -507,7 +507,8 @@ impl ClusterGateway for MemCluster {
|
||||
|
||||
use domain::ports::{FindingRepository, VulnerabilityScanner};
|
||||
use domain::vuln::{
|
||||
Finding, FindingFilter, FindingStatus, RawFinding, Severity, SeverityCounts, TargetKind,
|
||||
Finding, FindingFilter, FindingGroup, FindingStatus, RawFinding, Severity, SeverityCounts,
|
||||
TargetKind,
|
||||
};
|
||||
|
||||
pub fn raw(
|
||||
@ -630,6 +631,7 @@ impl FindingRepository for MemFindings {
|
||||
.filter(|f| filter.include_fixed || f.status != FindingStatus::Fixed)
|
||||
.filter(|f| filter.min_severity.is_none_or(|m| f.raw.severity >= m))
|
||||
.filter(|f| filter.target_kind.is_none_or(|k| f.target_kind == k))
|
||||
.filter(|f| filter.package.as_ref().is_none_or(|p| &f.raw.package == p))
|
||||
.filter(|f| filter.target.as_ref().is_none_or(|t| &f.target == t))
|
||||
.filter(|f| filter.status.is_none_or(|s| f.status == s))
|
||||
.cloned()
|
||||
@ -642,6 +644,71 @@ impl FindingRepository for MemFindings {
|
||||
});
|
||||
Ok(v)
|
||||
}
|
||||
async fn groups(&self, filter: &FindingFilter) -> Result<Vec<FindingGroup>, DomainError> {
|
||||
let per_image = filter.target_kind == Some(TargetKind::Image);
|
||||
let mut by_key: HashMap<String, FindingGroup> = HashMap::new();
|
||||
let mut packages: HashMap<String, std::collections::HashSet<String>> = HashMap::new();
|
||||
for f in self.list(filter).await? {
|
||||
let key = if per_image {
|
||||
f.target.clone()
|
||||
} else {
|
||||
f.raw.package.clone()
|
||||
};
|
||||
packages
|
||||
.entry(key.clone())
|
||||
.or_default()
|
||||
.insert(f.raw.package.clone());
|
||||
let g = by_key.entry(key.clone()).or_insert_with(|| FindingGroup {
|
||||
key,
|
||||
kind: f.target_kind,
|
||||
source: if per_image {
|
||||
String::new()
|
||||
} else {
|
||||
f.raw.source.clone()
|
||||
},
|
||||
installed: if per_image {
|
||||
String::new()
|
||||
} else {
|
||||
f.raw.installed_version.clone()
|
||||
},
|
||||
counts: SeverityCounts::default(),
|
||||
total: 0,
|
||||
fixable: 0,
|
||||
packages: 0,
|
||||
});
|
||||
g.counts.add(f.raw.severity);
|
||||
g.total += 1;
|
||||
if f.raw.fixed_version.is_some() {
|
||||
g.fixable += 1;
|
||||
}
|
||||
}
|
||||
let mut groups: Vec<FindingGroup> = by_key
|
||||
.into_values()
|
||||
.map(|mut g| {
|
||||
g.packages = packages.get(&g.key).map(|p| p.len()).unwrap_or(1);
|
||||
g
|
||||
})
|
||||
.collect();
|
||||
let worst = |g: &FindingGroup| {
|
||||
Severity::ALL
|
||||
.iter()
|
||||
.position(|s| match s {
|
||||
Severity::Critical => g.counts.critical > 0,
|
||||
Severity::High => g.counts.high > 0,
|
||||
Severity::Medium => g.counts.medium > 0,
|
||||
Severity::Low => g.counts.low > 0,
|
||||
Severity::Unknown => g.counts.unknown > 0,
|
||||
})
|
||||
.unwrap_or(usize::MAX)
|
||||
};
|
||||
groups.sort_by(|a, b| {
|
||||
worst(a)
|
||||
.cmp(&worst(b))
|
||||
.then(b.total.cmp(&a.total))
|
||||
.then(a.key.cmp(&b.key))
|
||||
});
|
||||
Ok(groups)
|
||||
}
|
||||
async fn counts(&self, kind: Option<TargetKind>) -> Result<SeverityCounts, DomainError> {
|
||||
let mut c = SeverityCounts::default();
|
||||
for f in
|
||||
|
||||
Reference in New Issue
Block a user