From a146f09935aa0d35aaea992125fa47bfbb29e4da Mon Sep 17 00:00:00 2001 From: Dennis Nemec Date: Thu, 3 Sep 2026 19:32:18 +0200 Subject: [PATCH] Use production-sized identifiers in the vulnerability fixture data The dev fixtures only had short package and version strings, so the layout tests never exercised the widths that made the real findings table overflow. Co-Authored-By: Claude Opus 5 --- backend/crates/infrastructure/src/trivy.rs | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/backend/crates/infrastructure/src/trivy.rs b/backend/crates/infrastructure/src/trivy.rs index 77aa815..f06558b 100644 --- a/backend/crates/infrastructure/src/trivy.rs +++ b/backend/crates/infrastructure/src/trivy.rs @@ -209,6 +209,18 @@ impl VulnerabilityScanner for FakeScanner { title: "apt: unsigned repository".into(), url: "https://avd.aquasec.com/nvd/cve-2011-3374".into(), }, + // production-sized identifiers: long Go module path, multi-version fix list + RawFinding { + cve_id: "GHSA-hrxh-6v49-42gf".into(), + severity: Severity::Medium, + package: "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp".into(), + installed_version: "2:2.6.2+samba4.17.12+dfsg-0+deb12u4".into(), + fixed_version: Some( + "3.31.6, 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f".into(), + ), + title: "otelhttp: unbounded cardinality metrics".into(), + url: "https://github.com/advisories/GHSA-hrxh-6v49-42gf".into(), + }, ]) } async fn scan_image(