Record and show that an image is already on its newest tag

An image that had been checked and is current looked exactly like one
that was never checked.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 20:37:46 +02:00
parent 1cb634afca
commit 4efff51aa7
6 changed files with 69 additions and 15 deletions

View File

@ -357,7 +357,7 @@ The server is reachable via `ssh softvisor` (as root). Findings from the inspect
| WP-02 | M1 (shell) / M2 (rest) | done | shell 2026-09-02; encrypted settings, SMTP, job runner, scheduler 2026-09-02 |
| WP-10 | M2 | done | 2026-09-02; snaps inventoried, no upstream check |
| WP-11 | M2 | done | 2026-09-02; runs as root via systemd, sudoers scoping deferred to WP-41; log via polling |
| WP-12 | M2 | done | 2026-09-02; overview, restart, scale, set image; upstream tag check not done |
| WP-12 | M2 | done | 2026-09-02; overview, restart, scale, set image; upstream tag check added 2026-09-03 with image update suggestions |
| WP-20 | M3 | done | 2026-09-02; Trivy rootfs + image scans, diff with first/last seen, fixed detection |
| WP-21 | M3 | done | 2026-09-02; findings split into host (OS/packages/applications) and container categories, acknowledge, mail digest with severity threshold |
| WP-30 | M4 | done | 2026-09-02; SMB via smbclient, FTP/FTPS via curl, credentials encrypted |

View File

@ -64,15 +64,21 @@ impl ImageUpdateService {
}
/// Scan the newest available tag and record which of the open findings it fixes.
pub async fn check(
&self,
image: &str,
log: &dyn JobLog,
) -> Result<Option<ImageUpdate>, DomainError> {
pub async fn check(&self, image: &str, log: &dyn JobLog) -> Result<ImageUpdate, DomainError> {
let Some(candidate) = self.candidate(image).await? else {
log.line(&format!("{image}: already on the newest tag"))
.await;
return Ok(None);
// record the check so the view can tell "current" from "never checked"
let update = ImageUpdate {
image: image.to_string(),
candidate: String::new(),
checked_at: Utc::now(),
fixed: Vec::new(),
fixed_counts: SeverityCounts::default(),
candidate_total: 0,
};
self.updates.upsert(&update).await?;
return Ok(update);
};
log.line(&format!("{image}: candidate {candidate}, scanning it"))
.await;
@ -124,7 +130,7 @@ impl ImageUpdateService {
update.candidate_total
))
.await;
Ok(Some(update))
Ok(update)
}
/// Check every image that currently runs on the cluster.
@ -138,8 +144,8 @@ impl ImageUpdateService {
let mut found = 0;
for image in images {
match self.check(&image, log).await {
Ok(Some(_)) => found += 1,
Ok(None) => {}
Ok(u) if !u.up_to_date() => found += 1,
Ok(_) => {}
Err(e) => log.line(&format!("{image}: check failed: {e}")).await,
}
}

View File

@ -92,7 +92,8 @@ async fn a_check_records_which_findings_the_candidate_fixes() {
seed(f.findings.clone(), running, Arc::new(MemCluster::default())).await;
let log = VecLog::default();
let update = svc.check(GITEA, &log).await.unwrap().unwrap();
let update = svc.check(GITEA, &log).await.unwrap();
assert!(!update.up_to_date());
assert_eq!(update.candidate, "gitea/gitea:1.23.0");
assert_eq!(update.fixed, vec!["CVE-1", "CVE-2"]);
assert_eq!(update.fixed_counts.critical, 1);
@ -111,11 +112,19 @@ async fn a_check_records_which_findings_the_candidate_fixes() {
}
#[tokio::test]
async fn nothing_is_recorded_when_the_image_is_current() {
async fn being_up_to_date_is_recorded_as_a_result_too() {
let (f, svc) = fixture(FakeScanner::default(), &["1.22.3"]);
let log = VecLog::default();
assert!(svc.check(GITEA, &log).await.unwrap().is_none());
assert!(f.updates.0.lock().unwrap().is_empty());
let update = svc.check(GITEA, &log).await.unwrap();
assert!(update.up_to_date(), "no newer tag exists");
assert!(update.candidate.is_empty());
assert!(update.fixed.is_empty());
// the result is stored, so the view can tell "checked and current" from "never checked"
assert_eq!(f.updates.0.lock().unwrap().len(), 1);
assert_eq!(
svc.stored(GITEA).await.unwrap().unwrap().checked_at,
update.checked_at
);
assert!(log
.0
.lock()

View File

@ -59,6 +59,7 @@ pub struct ImageUpdate {
/// The image reference as it runs on the cluster.
pub image: String,
/// The newer tag that was checked, e.g. `docker.gitea.com/gitea:1.25.1-rootless`.
/// Empty when the check found no newer tag.
pub candidate: String,
pub checked_at: chrono::DateTime<chrono::Utc>,
/// CVE ids that are open on the running image and gone in the candidate.
@ -68,6 +69,13 @@ pub struct ImageUpdate {
pub candidate_total: usize,
}
impl ImageUpdate {
/// True when the check found no newer tag for this image.
pub fn up_to_date(&self) -> bool {
self.candidate.is_empty()
}
}
/// Numeric parts of a tag plus its suffix, e.g. `1.24.2-rootless` → ([1, 24, 2], "rootless").
fn version_parts(tag: &str) -> Option<(Vec<u64>, String)> {
let core = tag.strip_prefix('v').unwrap_or(tag);

View File

@ -151,6 +151,26 @@ describe('FindingGroups for images', () => {
expect(w.find('button[name=update-image]').exists()).toBe(true)
})
it('says the image is current when a check found no newer tag', () => {
const current = image({
update: {
image: 'gitea/gitea:1.22.3',
candidate: '',
checked_at: '2026-09-03T08:00:00Z',
fixed: [],
fixed_counts: { critical: 0, high: 0, medium: 0, low: 0, unknown: 0 },
candidate_total: 0,
},
})
const w = mount(FindingGroups, {
props: { groups: [current], scope: 'container', canAct: true, load: vi.fn() },
global: { stubs: { RouterLink: { template: '<a><slot /></a>' } } },
})
expect(w.text()).toContain('newest tag')
expect(w.find('button[name=update-image]').exists()).toBe(false)
expect(w.find('button[name=check-image]').exists()).toBe(true)
})
it('offers a check when nothing is known yet and hides the actions from viewers', () => {
const w = mount(FindingGroups, {
props: { groups: [image()], scope: 'container', canAct: true, load: vi.fn() },

View File

@ -127,7 +127,18 @@ const shown = (c: SeverityCounts) => chips.filter((s) => c[s.key] > 0)
</span>
</td>
<td v-if="scope === 'container'" class="whitespace-nowrap text-xs" @click.stop>
<template v-if="asImage(g).update">
<template v-if="asImage(g).update && !asImage(g).update!.candidate">
<div class="text-gray-500">on the newest tag</div>
<button
v-if="canAct"
name="check-image"
class="text-blue-600 hover:underline"
@click="emit('check', asImage(g))"
>
Check again
</button>
</template>
<template v-else-if="asImage(g).update">
<div>
<span class="font-mono font-medium text-green-700">{{
tagOf(asImage(g).update!.candidate)