Use production-sized identifiers in the vulnerability fixture data

The dev fixtures only had short package and version strings, so the
layout tests never exercised the widths that made the real findings
table overflow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 19:32:18 +02:00
parent 7e606cc884
commit a146f09935

View File

@ -209,6 +209,18 @@ impl VulnerabilityScanner for FakeScanner {
title: "apt: unsigned repository".into(),
url: "https://avd.aquasec.com/nvd/cve-2011-3374".into(),
},
// production-sized identifiers: long Go module path, multi-version fix list
RawFinding {
cve_id: "GHSA-hrxh-6v49-42gf".into(),
severity: Severity::Medium,
package: "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp".into(),
installed_version: "2:2.6.2+samba4.17.12+dfsg-0+deb12u4".into(),
fixed_version: Some(
"3.31.6, 1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f".into(),
),
title: "otelhttp: unbounded cardinality metrics".into(),
url: "https://github.com/advisories/GHSA-hrxh-6v49-42gf".into(),
},
])
}
async fn scan_image(