The findings table listed every CVE, which is thousands of rows on a real host. It now shows one row per affected package (host) or image (containers) with its severity split, how many findings it has and how many of them have a fix. Clicking a row loads and shows the CVEs of that group; collapsing keeps them cached. The rollup is a GROUP BY in SQLite behind a new groups endpoint, so the page loads a few dozen rows instead of the full finding list, and the flat list gained a package filter to expand one group. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
36 lines
1.6 KiB
TypeScript
36 lines
1.6 KiB
TypeScript
import { test, expect, type Page } from '@playwright/test'
|
|
|
|
async function scan(page: Page) {
|
|
await page.goto('/login')
|
|
await page.getByLabel('Email').fill('admin@example.com')
|
|
await page.getByLabel('Password').fill('admin-password-123')
|
|
await page.getByRole('button', { name: 'Sign in' }).click()
|
|
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
|
|
await page.goto('/vulnerabilities')
|
|
await page.getByRole('button', { name: 'Scan now' }).click()
|
|
await expect(page.getByTestId('scope-host-critical')).not.toHaveText('0', { timeout: 20_000 })
|
|
}
|
|
|
|
test('packages and images are one row each and expand to their CVEs', async ({ page }) => {
|
|
await scan(page)
|
|
|
|
// host: a row per package, no CVE ids until a row is opened
|
|
const zlib = page.getByRole('row', { name: /zlib1g/ })
|
|
await expect(zlib).toBeVisible()
|
|
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toHaveCount(0)
|
|
|
|
await zlib.click()
|
|
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toBeVisible()
|
|
await expect(zlib).toHaveAttribute('aria-expanded', 'true')
|
|
await zlib.click()
|
|
await expect(page.getByRole('row', { name: /CVE-2023-45853/ })).toHaveCount(0)
|
|
|
|
// containers: a row per image that expands to the CVEs of that image
|
|
await page.getByTestId('scope-container').click()
|
|
const image = page.getByRole('row', { name: /gitea\/gitea/ }).first()
|
|
await expect(image).toBeVisible()
|
|
await expect(page.getByRole('row', { name: /CVE-2024-24790/ })).toHaveCount(0)
|
|
await image.click()
|
|
await expect(page.getByRole('row', { name: /CVE-2024-24790/ })).toBeVisible()
|
|
})
|