Split the vulnerability view into host and container categories
The findings of the Debian host (OS packages and applications found in the root filesystem) and of the container images in the cluster were mixed in one flat table. They are now two prominent categories: a card each with its own severity split and target count, acting as the primary selector, and a table that adapts to the selection. Host findings show the package source reported by the scanner (debian, gobinary, node-pkg …) instead of the target, container findings show the image. Backend: findings carry the scanner's package source, the list endpoint takes ?scope=host|container, and the targets endpoint reports each target with its category and open count. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@ -43,7 +43,7 @@ impl Severity {
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq, Hash, PartialOrd, Ord, Serialize, Deserialize)]
|
||||
#[serde(rename_all = "lowercase")]
|
||||
pub enum TargetKind {
|
||||
Os,
|
||||
@ -51,6 +51,30 @@ pub enum TargetKind {
|
||||
}
|
||||
|
||||
impl TargetKind {
|
||||
/// Category shown to the user: the Debian host, or the container images in the cluster.
|
||||
pub fn label(self) -> &'static str {
|
||||
match self {
|
||||
TargetKind::Os => "Host",
|
||||
TargetKind::Image => "Containers",
|
||||
}
|
||||
}
|
||||
|
||||
/// Scope name used by the API (`?scope=`).
|
||||
pub fn scope(self) -> &'static str {
|
||||
match self {
|
||||
TargetKind::Os => "host",
|
||||
TargetKind::Image => "container",
|
||||
}
|
||||
}
|
||||
|
||||
pub fn parse_scope(s: &str) -> Option<TargetKind> {
|
||||
match s {
|
||||
"host" => Some(TargetKind::Os),
|
||||
"container" => Some(TargetKind::Image),
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
pub fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
TargetKind::Os => "os",
|
||||
@ -102,6 +126,10 @@ pub struct RawFinding {
|
||||
pub fixed_version: Option<String>,
|
||||
pub title: String,
|
||||
pub url: String,
|
||||
/// Package source reported by the scanner: `debian` for OS packages, `gobinary`,
|
||||
/// `node-pkg`, `python-pkg` … for applications and libraries found on the target.
|
||||
#[serde(default)]
|
||||
pub source: String,
|
||||
}
|
||||
|
||||
impl RawFinding {
|
||||
@ -130,6 +158,8 @@ pub struct Finding {
|
||||
#[derive(Clone, Debug, Default, PartialEq, Eq)]
|
||||
pub struct FindingFilter {
|
||||
pub min_severity: Option<Severity>,
|
||||
/// Restrict to one category (host or containers).
|
||||
pub target_kind: Option<TargetKind>,
|
||||
pub target: Option<String>,
|
||||
pub status: Option<FindingStatus>,
|
||||
/// Include fixed findings (default: only open + acknowledged).
|
||||
|
||||
Reference in New Issue
Block a user