Roll findings up per package and image, expandable to their CVEs

The findings table listed every CVE, which is thousands of rows on a real
host. It now shows one row per affected package (host) or image
(containers) with its severity split, how many findings it has and how
many of them have a fix. Clicking a row loads and shows the CVEs of that
group; collapsing keeps them cached.

The rollup is a GROUP BY in SQLite behind a new groups endpoint, so the
page loads a few dozen rows instead of the full finding list, and the
flat list gained a package filter to expand one group.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 20:02:25 +02:00
parent 751296b3b0
commit 278b5e47a3
14 changed files with 635 additions and 59 deletions

View File

@ -496,7 +496,8 @@ impl domain::ports::InventoryRepository for SqliteInventory {
}
use domain::vuln::{
Finding, FindingFilter, FindingStatus, RawFinding, Severity, SeverityCounts, TargetKind,
Finding, FindingFilter, FindingGroup, FindingStatus, RawFinding, Severity, SeverityCounts,
TargetKind,
};
pub struct SqliteFindings(pub DbPool);
@ -629,6 +630,9 @@ impl domain::ports::FindingRepository for SqliteFindings {
if filter.target_kind.is_some() {
sql.push_str(" AND target_kind = ?");
}
if filter.package.is_some() {
sql.push_str(" AND package = ?");
}
if filter.min_severity.is_some() {
sql.push_str(&format!(" AND {SEVERITY_RANK_SQL} >= ?"));
}
@ -645,6 +649,9 @@ impl domain::ports::FindingRepository for SqliteFindings {
if let Some(k) = filter.target_kind {
q = q.bind(k.as_str());
}
if let Some(p) = &filter.package {
q = q.bind(p);
}
if let Some(m) = filter.min_severity {
q = q.bind(severity_rank(m));
}
@ -653,6 +660,94 @@ impl domain::ports::FindingRepository for SqliteFindings {
.map(|rows| rows.iter().map(finding_from_row).collect())
.map_err(storage)
}
async fn groups(&self, filter: &FindingFilter) -> Result<Vec<FindingGroup>, DomainError> {
// Host findings roll up per package, container findings per image.
let per_image = filter.target_kind == Some(TargetKind::Image);
let key = if per_image { "target" } else { "package" };
let mut sql = format!(
"SELECT {key} AS key, target_kind, \
COALESCE(MAX(source), '') AS source, COALESCE(MAX(installed_version), '') AS installed, \
COUNT(*) AS total, \
SUM(fixed_version IS NOT NULL AND fixed_version != '') AS fixable, \
COUNT(DISTINCT package) AS packages, \
SUM(severity = 'critical') AS critical, SUM(severity = 'high') AS high, \
SUM(severity = 'medium') AS medium, SUM(severity = 'low') AS low, \
SUM(severity NOT IN ('critical', 'high', 'medium', 'low')) AS unknown \
FROM findings WHERE 1=1"
);
if !filter.include_fixed {
sql.push_str(" AND status != 'fixed'");
}
if filter.status.is_some() {
sql.push_str(" AND status = ?");
}
if filter.target.is_some() {
sql.push_str(" AND target = ?");
}
if filter.target_kind.is_some() {
sql.push_str(" AND target_kind = ?");
}
if filter.package.is_some() {
sql.push_str(" AND package = ?");
}
if filter.min_severity.is_some() {
sql.push_str(&format!(" AND {SEVERITY_RANK_SQL} >= ?"));
}
// worst severity first, then most findings, then by name
sql.push_str(&format!(
" GROUP BY {key}, target_kind ORDER BY MAX({SEVERITY_RANK_SQL}) DESC, total DESC, key"
));
let mut q = sqlx::query(&sql);
if let Some(st) = filter.status {
q = q.bind(st.as_str());
}
if let Some(t) = &filter.target {
q = q.bind(t);
}
if let Some(k) = filter.target_kind {
q = q.bind(k.as_str());
}
if let Some(p) = &filter.package {
q = q.bind(p);
}
if let Some(m) = filter.min_severity {
q = q.bind(severity_rank(m));
}
let rows = q.fetch_all(&self.0).await.map_err(storage)?;
Ok(rows
.iter()
.map(|r| {
let n = |c: &str| r.get::<i64, _>(c) as usize;
let kind = TargetKind::parse(r.get::<String, _>("target_kind").as_str())
.unwrap_or(TargetKind::Os);
FindingGroup {
key: r.get("key"),
kind,
source: if kind == TargetKind::Image {
String::new()
} else {
r.get("source")
},
installed: if kind == TargetKind::Image {
String::new()
} else {
r.get("installed")
},
counts: SeverityCounts {
critical: n("critical"),
high: n("high"),
medium: n("medium"),
low: n("low"),
unknown: n("unknown"),
},
total: n("total"),
fixable: n("fixable"),
packages: n("packages"),
}
})
.collect())
}
async fn counts(&self, kind: Option<TargetKind>) -> Result<SeverityCounts, DomainError> {
let sql = match kind {
Some(_) => "SELECT severity, COUNT(*) FROM findings WHERE status != 'fixed' AND target_kind = ? GROUP BY severity",
@ -807,6 +902,77 @@ mod finding_tests {
"source survives the roundtrip"
);
}
#[tokio::test]
async fn groups_roll_up_per_package_and_per_image() {
let pool = crate::connect("sqlite::memory:").await.unwrap();
let repo = SqliteFindings(pool);
let mut a = finding("os", TargetKind::Os, "CVE-A", Severity::Critical);
a.raw.package = "openssl".into();
a.raw.fixed_version = Some("3.0.2".into());
let mut b = finding("os", TargetKind::Os, "CVE-B", Severity::Low);
b.raw.package = "openssl".into();
let mut c = finding("os", TargetKind::Os, "CVE-C", Severity::High);
c.raw.package = "stdlib".into();
c.raw.source = "gobinary".into();
let mut d = finding("img:1", TargetKind::Image, "CVE-D", Severity::Medium);
d.raw.package = "curl".into();
let mut e = finding("img:1", TargetKind::Image, "CVE-E", Severity::High);
e.raw.package = "git".into();
for f in [&a, &b, &c, &d, &e] {
repo.insert(f).await.unwrap();
}
let host = repo
.groups(&FindingFilter {
target_kind: Some(TargetKind::Os),
..Default::default()
})
.await
.unwrap();
assert_eq!(
host.iter().map(|g| g.key.as_str()).collect::<Vec<_>>(),
vec!["openssl", "stdlib"]
);
assert_eq!(host[0].counts.critical, 1);
assert_eq!(host[0].counts.low, 1);
assert_eq!(host[0].total, 2);
assert_eq!(host[0].fixable, 1);
assert_eq!(host[0].installed, "1");
assert_eq!(host[1].source, "gobinary");
let images = repo
.groups(&FindingFilter {
target_kind: Some(TargetKind::Image),
..Default::default()
})
.await
.unwrap();
assert_eq!(images.len(), 1);
assert_eq!(images[0].key, "img:1");
assert_eq!(images[0].total, 2);
assert_eq!(images[0].packages, 2);
// fixed findings stay out unless asked for, and the package filter drills in
repo.set_status(b.id, FindingStatus::Fixed).await.unwrap();
let host = repo
.groups(&FindingFilter {
target_kind: Some(TargetKind::Os),
..Default::default()
})
.await
.unwrap();
assert_eq!(host[0].total, 1);
let drilled = repo
.list(&FindingFilter {
package: Some("stdlib".into()),
..Default::default()
})
.await
.unwrap();
assert_eq!(drilled.len(), 1);
assert_eq!(drilled[0].raw.cve_id, "CVE-C");
}
}
use domain::backup::{BackupRecord, BackupSource, BackupStrategy, BackupTarget, StorageKind};

View File

@ -202,6 +202,17 @@ impl VulnerabilityScanner for FakeScanner {
url: "https://avd.aquasec.com/nvd/cve-2024-5535".into(),
source: "debian".into(),
},
// a second flaw in the same package: the grouped view collapses both into one row
RawFinding {
cve_id: "CVE-2024-2511".into(),
severity: Severity::Medium,
package: "openssl".into(),
installed_version: "3.0.15-1~deb12u1".into(),
fixed_version: Some("3.0.16-1~deb12u1".into()),
title: "openssl: unbounded memory growth in the session cache".into(),
url: "https://avd.aquasec.com/nvd/cve-2024-2511".into(),
source: "debian".into(),
},
RawFinding {
cve_id: "CVE-2023-45853".into(),
severity: Severity::Critical,