Link image findings to their workloads and suggest a fixing image update
Container findings now name the workloads that run the image and link into the Kubernetes view, which highlights them. An update check asks the registry for newer tags of the same variant, scans the newest one and records which of the open findings are gone in it. The image row then shows the candidate tag, how many findings it fixes and how many remain, marks those CVEs in the expanded list, and offers to roll every workload over to it. The check runs as a job, nightly for all running images or on demand for one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
36
frontend/e2e/image-updates.spec.ts
Normal file
36
frontend/e2e/image-updates.spec.ts
Normal file
@ -0,0 +1,36 @@
|
||||
import { test, expect, type Page } from '@playwright/test'
|
||||
|
||||
async function scanAndOpenContainers(page: Page) {
|
||||
await page.goto('/login')
|
||||
await page.getByLabel('Email').fill('admin@example.com')
|
||||
await page.getByLabel('Password').fill('admin-password-123')
|
||||
await page.getByRole('button', { name: 'Sign in' }).click()
|
||||
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
|
||||
await page.goto('/vulnerabilities')
|
||||
await page.getByRole('button', { name: 'Scan now' }).click()
|
||||
await expect(page.getByTestId('scope-host-critical')).not.toHaveText('0', { timeout: 20_000 })
|
||||
await page.getByTestId('scope-container').click()
|
||||
}
|
||||
|
||||
test('an image finding links to the workload running it', async ({ page }) => {
|
||||
await scanAndOpenContainers(page)
|
||||
const row = page.getByRole('row', { name: /gitea\/gitea/ }).first()
|
||||
await expect(row).toContainText('gitea/deployment/gitea')
|
||||
|
||||
await row.getByRole('link', { name: 'gitea/deployment/gitea' }).click()
|
||||
await expect(page).toHaveURL(/\/cluster\?image=/)
|
||||
await expect(page.getByText('Showing the workloads that run')).toBeVisible()
|
||||
await expect(page.getByRole('row', { name: /gitea gitea deployment/ })).toBeVisible()
|
||||
})
|
||||
|
||||
test('checking an image suggests a newer tag and marks the CVEs it fixes', async ({ page }) => {
|
||||
await scanAndOpenContainers(page)
|
||||
const row = page.getByRole('row', { name: /gitea\/gitea/ }).first()
|
||||
await row.getByRole('button', { name: 'Check for update' }).click()
|
||||
await expect(row).toContainText('9.9.9', { timeout: 20_000 })
|
||||
await expect(row).toContainText('fixes 1')
|
||||
|
||||
await row.click()
|
||||
await expect(page.getByRole('row', { name: /CVE-2024-24790/ })).toContainText('fixed in 9.9.9')
|
||||
await expect(row.getByRole('button', { name: /Update to 9.9.9/ })).toBeVisible()
|
||||
})
|
||||
Reference in New Issue
Block a user