Refresh scanner details of findings that are seen again

A rescan only touched the timestamp of findings it had seen before, so a
newly published fix version, a changed severity and the package source
never reached existing rows. The repository now updates those fields
while keeping first_seen and the status the user set.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 19:50:18 +02:00
parent aba2c69416
commit 70cf25fc7f
5 changed files with 93 additions and 23 deletions

View File

@ -140,9 +140,11 @@ pub trait FindingRepository: Send + Sync {
/// Open and acknowledged findings of one target.
async fn active_by_target(&self, target: &str) -> Result<Vec<Finding>, DomainError>;
async fn insert(&self, finding: &Finding) -> Result<(), DomainError>;
async fn touch(
/// Mark findings as seen again and update the details the scanner may have changed
/// (severity, fix version, title, source).
async fn refresh(
&self,
ids: &[Uuid],
updates: &[(Uuid, RawFinding)],
last_seen: chrono::DateTime<chrono::Utc>,
) -> Result<(), DomainError>;
async fn set_status(&self, id: Uuid, status: FindingStatus) -> Result<(), DomainError>;