Roll findings up per package and image, expandable to their CVEs

The findings table listed every CVE, which is thousands of rows on a real
host. It now shows one row per affected package (host) or image
(containers) with its severity split, how many findings it has and how
many of them have a fix. Clicking a row loads and shows the CVEs of that
group; collapsing keeps them cached.

The rollup is a GROUP BY in SQLite behind a new groups endpoint, so the
page loads a few dozen rows instead of the full finding list, and the
flat list gained a package filter to expand one group.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 20:02:25 +02:00
parent 751296b3b0
commit 278b5e47a3
14 changed files with 635 additions and 59 deletions

View File

@ -9,13 +9,15 @@ test('admin runs a scan, filters findings and acknowledges one', async ({ page }
await page.getByRole('button', { name: 'Scan now' }).click()
await expect(page.getByTestId('scope-host-critical')).not.toHaveText('0', { timeout: 20_000 })
await page.getByRole('row', { name: /zlib1g/ }).click()
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toBeVisible()
await page.getByLabel('Minimum severity').selectOption('critical')
await expect(page.getByRole('row', { name: /CVE-2011-3374/ })).toHaveCount(0)
await expect(page.getByRole('row', { name: /apt/ })).toHaveCount(0)
await page.getByLabel('Minimum severity').selectOption('low')
await expect(page.getByRole('row', { name: /CVE-2011-3374/ })).toBeVisible()
await expect(page.getByRole('row', { name: /apt/ })).toBeVisible()
await page.getByRole('row', { name: /zlib1g/ }).click()
const row = page.getByRole('row', { name: /CVE-2023-45853/ })
await row.getByRole('button', { name: 'Acknowledge' }).click()
await expect(row).toContainText('acknowledged')