Roll findings up per package and image, expandable to their CVEs
The findings table listed every CVE, which is thousands of rows on a real host. It now shows one row per affected package (host) or image (containers) with its severity split, how many findings it has and how many of them have a fix. Clicking a row loads and shows the CVEs of that group; collapsing keeps them cached. The rollup is a GROUP BY in SQLite behind a new groups endpoint, so the page loads a few dozen rows instead of the full finding list, and the flat list gained a package filter to expand one group. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@ -15,7 +15,7 @@ test('packages and images are one row each and expand to their CVEs', async ({ p
|
||||
await scan(page)
|
||||
|
||||
// host: a row per package, no CVE ids until a row is opened
|
||||
const zlib = page.getByRole('row', { name: /^zlib1g/ })
|
||||
const zlib = page.getByRole('row', { name: /zlib1g/ })
|
||||
await expect(zlib).toBeVisible()
|
||||
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toHaveCount(0)
|
||||
|
||||
|
||||
@ -19,19 +19,18 @@ test('host and container findings are separated into two categories', async ({ p
|
||||
await expect(page.getByTestId('scope-container')).toContainText('images')
|
||||
await expect(page.getByTestId('scope-container-critical')).not.toHaveText('0')
|
||||
|
||||
// host is selected first and shows only host findings, with the package source
|
||||
// host is selected first and lists host packages with their source
|
||||
await expect(page.getByTestId('scope-host')).toHaveAttribute('aria-pressed', 'true')
|
||||
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toBeVisible()
|
||||
await expect(page.getByRole('row', { name: /CVE-2024-24790/ })).toHaveCount(0)
|
||||
await expect(page.getByRole('row', { name: /zlib1g/ })).toBeVisible()
|
||||
await expect(page.getByRole('row', { name: /gitea\/gitea/ })).toHaveCount(0)
|
||||
await expect(page.getByTestId('findings-scroll')).toContainText('Source')
|
||||
|
||||
// switching to containers swaps the table
|
||||
await page.getByTestId('scope-container').click()
|
||||
await expect(page.getByTestId('scope-container')).toHaveAttribute('aria-pressed', 'true')
|
||||
await expect(page.getByRole('row', { name: /CVE-2024-24790/ })).toBeVisible()
|
||||
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toHaveCount(0)
|
||||
await expect(page.getByTestId('findings-scroll')).toContainText('Image')
|
||||
await expect(page.getByRole('row', { name: /gitea\/gitea/ }).first()).toBeVisible()
|
||||
await expect(page.getByRole('row', { name: /zlib1g/ })).toHaveCount(0)
|
||||
await expect(page.getByTestId('findings-scroll')).toContainText('Image')
|
||||
|
||||
// the filter is labelled per category and only offers targets of that category
|
||||
const images = await page.getByLabel('Image', { exact: true }).locator('option').allTextContents()
|
||||
|
||||
@ -9,13 +9,15 @@ test('admin runs a scan, filters findings and acknowledges one', async ({ page }
|
||||
|
||||
await page.getByRole('button', { name: 'Scan now' }).click()
|
||||
await expect(page.getByTestId('scope-host-critical')).not.toHaveText('0', { timeout: 20_000 })
|
||||
await page.getByRole('row', { name: /zlib1g/ }).click()
|
||||
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toBeVisible()
|
||||
|
||||
await page.getByLabel('Minimum severity').selectOption('critical')
|
||||
await expect(page.getByRole('row', { name: /CVE-2011-3374/ })).toHaveCount(0)
|
||||
await expect(page.getByRole('row', { name: /apt/ })).toHaveCount(0)
|
||||
await page.getByLabel('Minimum severity').selectOption('low')
|
||||
await expect(page.getByRole('row', { name: /CVE-2011-3374/ })).toBeVisible()
|
||||
await expect(page.getByRole('row', { name: /apt/ })).toBeVisible()
|
||||
|
||||
await page.getByRole('row', { name: /zlib1g/ }).click()
|
||||
const row = page.getByRole('row', { name: /CVE-2023-45853/ })
|
||||
await row.getByRole('button', { name: 'Acknowledge' }).click()
|
||||
await expect(row).toContainText('acknowledged')
|
||||
|
||||
Reference in New Issue
Block a user