Roll findings up per package and image, expandable to their CVEs
The findings table listed every CVE, which is thousands of rows on a real host. It now shows one row per affected package (host) or image (containers) with its severity split, how many findings it has and how many of them have a fix. Clicking a row loads and shows the CVEs of that group; collapsing keeps them cached. The rollup is a GROUP BY in SQLite behind a new groups endpoint, so the page loads a few dozen rows instead of the full finding list, and the flat list gained a package filter to expand one group. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@ -417,17 +417,38 @@ async fn host_findings_are_grouped_per_package_and_containers_per_image() {
|
||||
.with(
|
||||
"os",
|
||||
Ok(vec![
|
||||
raw("CVE-1", "openssl", "3.0.1", Severity::Critical, Some("3.0.2")),
|
||||
raw(
|
||||
"CVE-1",
|
||||
"openssl",
|
||||
"3.0.1",
|
||||
Severity::Critical,
|
||||
Some("3.0.2"),
|
||||
),
|
||||
raw("CVE-2", "openssl", "3.0.1", Severity::Low, None),
|
||||
go,
|
||||
]),
|
||||
)
|
||||
.with(GITEA, Ok(vec![raw("CVE-3", "git", "2.39", Severity::High, None), raw("CVE-4", "curl", "7.8", Severity::Medium, None)]))
|
||||
.with(PG, Ok(vec![raw("CVE-5", "libssl3", "3.0", Severity::Low, None)]));
|
||||
.with(
|
||||
GITEA,
|
||||
Ok(vec![
|
||||
raw("CVE-3", "git", "2.39", Severity::High, None),
|
||||
raw("CVE-4", "curl", "7.8", Severity::Medium, None),
|
||||
]),
|
||||
)
|
||||
.with(
|
||||
PG,
|
||||
Ok(vec![raw("CVE-5", "libssl3", "3.0", Severity::Low, None)]),
|
||||
);
|
||||
let (_f, svc) = fixture(scanner);
|
||||
svc.scan(&VecLog::default()).await.unwrap();
|
||||
|
||||
let host = svc.groups(FindingFilter { target_kind: Some(TargetKind::Os), ..Default::default() }).await.unwrap();
|
||||
let host = svc
|
||||
.groups(FindingFilter {
|
||||
target_kind: Some(TargetKind::Os),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(host.len(), 2, "one row per package, not per CVE");
|
||||
// worst severity first
|
||||
assert_eq!(host[0].key, "openssl");
|
||||
@ -440,30 +461,75 @@ async fn host_findings_are_grouped_per_package_and_containers_per_image() {
|
||||
assert_eq!(host[1].key, "stdlib");
|
||||
assert_eq!(host[1].source, "gobinary");
|
||||
|
||||
let images = svc.groups(FindingFilter { target_kind: Some(TargetKind::Image), ..Default::default() }).await.unwrap();
|
||||
assert_eq!(images.iter().map(|g| g.key.as_str()).collect::<Vec<_>>(), vec![GITEA, PG]);
|
||||
let images = svc
|
||||
.groups(FindingFilter {
|
||||
target_kind: Some(TargetKind::Image),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
images.iter().map(|g| g.key.as_str()).collect::<Vec<_>>(),
|
||||
vec![GITEA, PG]
|
||||
);
|
||||
assert_eq!(images[0].total, 2);
|
||||
assert_eq!(images[0].packages, 2, "distinct packages in the image");
|
||||
|
||||
// the group list honours the other filters
|
||||
let high = svc
|
||||
.groups(FindingFilter { target_kind: Some(TargetKind::Os), min_severity: Some(Severity::High), ..Default::default() })
|
||||
.groups(FindingFilter {
|
||||
target_kind: Some(TargetKind::Os),
|
||||
min_severity: Some(Severity::High),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(high.iter().map(|g| g.key.as_str()).collect::<Vec<_>>(), vec!["openssl", "stdlib"]);
|
||||
assert_eq!(high[0].total, 1, "the low finding is filtered out of the counts");
|
||||
assert_eq!(
|
||||
high.iter().map(|g| g.key.as_str()).collect::<Vec<_>>(),
|
||||
vec!["openssl", "stdlib"]
|
||||
);
|
||||
assert_eq!(
|
||||
high[0].total, 1,
|
||||
"the low finding is filtered out of the counts"
|
||||
);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn findings_of_one_group_can_be_listed() {
|
||||
let scanner = FakeScanner::default()
|
||||
.with("os", Ok(vec![raw("CVE-1", "openssl", "3.0.1", Severity::Critical, None), raw("CVE-2", "bash", "5.2", Severity::Low, None)]))
|
||||
.with(GITEA, Ok(vec![raw("CVE-3", "git", "2.39", Severity::High, None)]));
|
||||
.with(
|
||||
"os",
|
||||
Ok(vec![
|
||||
raw("CVE-1", "openssl", "3.0.1", Severity::Critical, None),
|
||||
raw("CVE-2", "bash", "5.2", Severity::Low, None),
|
||||
]),
|
||||
)
|
||||
.with(
|
||||
GITEA,
|
||||
Ok(vec![raw("CVE-3", "git", "2.39", Severity::High, None)]),
|
||||
);
|
||||
let (_f, svc) = fixture(scanner);
|
||||
svc.scan(&VecLog::default()).await.unwrap();
|
||||
|
||||
let pkg = svc.list(FindingFilter { package: Some("openssl".into()), ..Default::default() }).await.unwrap();
|
||||
assert_eq!(pkg.iter().map(|f| f.raw.cve_id.as_str()).collect::<Vec<_>>(), vec!["CVE-1"]);
|
||||
let image = svc.list(FindingFilter { target: Some(GITEA.into()), ..Default::default() }).await.unwrap();
|
||||
let pkg = svc
|
||||
.list(FindingFilter {
|
||||
package: Some("openssl".into()),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
pkg.iter()
|
||||
.map(|f| f.raw.cve_id.as_str())
|
||||
.collect::<Vec<_>>(),
|
||||
vec!["CVE-1"]
|
||||
);
|
||||
let image = svc
|
||||
.list(FindingFilter {
|
||||
target: Some(GITEA.into()),
|
||||
..Default::default()
|
||||
})
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(image.len(), 1);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user