Refresh scanner details of findings that are seen again

A rescan only touched the timestamp of findings it had seen before, so a
newly published fix version, a changed severity and the package source
never reached existing rows. The repository now updates those fields
while keeping first_seen and the status the user set.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 19:50:18 +02:00
parent aba2c69416
commit 70cf25fc7f
5 changed files with 93 additions and 23 deletions

View File

@ -574,14 +574,25 @@ impl domain::ports::FindingRepository for SqliteFindings {
.map(|_| ())
.map_err(storage)
}
async fn touch(&self, ids: &[Uuid], last_seen: DateTime<Utc>) -> Result<(), DomainError> {
for id in ids {
sqlx::query("UPDATE findings SET last_seen = ? WHERE id = ?")
.bind(last_seen.to_rfc3339())
.bind(id)
.execute(&self.0)
.await
.map_err(storage)?;
async fn refresh(
&self,
updates: &[(Uuid, RawFinding)],
last_seen: DateTime<Utc>,
) -> Result<(), DomainError> {
for (id, raw) in updates {
sqlx::query(
"UPDATE findings SET last_seen = ?, severity = ?, fixed_version = ?, title = ?, url = ?, source = ? WHERE id = ?",
)
.bind(last_seen.to_rfc3339())
.bind(raw.severity.as_str())
.bind(&raw.fixed_version)
.bind(&raw.title)
.bind(&raw.url)
.bind(&raw.source)
.bind(id)
.execute(&self.0)
.await
.map_err(storage)?;
}
Ok(())
}
@ -752,8 +763,16 @@ mod finding_tests {
assert_eq!(repo.counts(Some(TargetKind::Os)).await.unwrap().critical, 1);
let later = Utc::now() + chrono::Duration::hours(1);
repo.touch(&[a.id], later).await.unwrap();
assert!(repo.get(a.id).await.unwrap().unwrap().last_seen > a.last_seen);
let fixed = RawFinding {
fixed_version: Some("2.0".into()),
source: "gobinary".into(),
..a.raw.clone()
};
repo.refresh(&[(a.id, fixed)], later).await.unwrap();
let refreshed = repo.get(a.id).await.unwrap().unwrap();
assert!(refreshed.last_seen > a.last_seen);
assert_eq!(refreshed.raw.fixed_version.as_deref(), Some("2.0"));
assert_eq!(refreshed.raw.source, "gobinary");
assert_eq!(
repo.set_status(Uuid::new_v4(), FindingStatus::Open)
.await