Skip to content

ROX-35970: Add CVE Origin UI - #22464

Merged
dcaravel merged 6 commits into
masterfrom
dc/cve-origin-ui-display
Aug 26, 2026
Merged

dcaravel merged 6 commits into
masterfrom
dc/cve-origin-ui-display

Conversation

@dcaravel

@dcaravel dcaravel commented Aug 26, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Adds new CVE Origin field to the single image and deployment pages. The field is added to the aggregate CVE rows as well as individual component rows.

Also adds severity and CVSS columns to the image component rows.

The origin field is conditional on Scanner V4 being enabled (similar to EPSS).

User-facing documentation

Testing and quality

  • the change is production ready: the change is GA, or otherwise the functionality is gated by a feature flag
  • CI results are inspected

Automated testing

  • added unit tests

How I validated my change

CI + Manual testing

Image page:

image image

Deployment Page:

image

Info Popover:

image

CVE Origin column is hidden when Scanner V4 Disabled:

image image

@openshift-ci

openshift-ci Bot commented Aug 26, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@coderabbitai

coderabbitai Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 3dbc845a-4356-476e-941f-8a971a13e3d6

📥 Commits

Reviewing files that changed from the base of the PR and between 858456a and e9c0856.

📒 Files selected for processing (2)
  • ui/apps/platform/src/Containers/Vulnerabilities/utils/vulnerabilityUtils.test.ts
  • ui/apps/platform/src/Containers/Vulnerabilities/utils/vulnerabilityUtils.ts

Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Summary by CodeRabbit

  • New Features
    • Added CVE origin information to image and deployment vulnerability tables.
    • Added CVSS scores, score versions, severity details, and origin labels to image component findings.
    • Added version-aware help text explaining CVE origins.
  • Enhancements
    • CVE origin columns are shown or hidden based on Scanner V4 availability.
    • Origin values are aggregated across related components, including “Multiple” and “Other” labels.
  • Bug Fixes
    • Improved consistency of vulnerability details and table row formatting across views.

Walkthrough

The vulnerability tables now retrieve CVSS, score version, and CVE origin data. They render origin values for image and deployment vulnerabilities. ROX_SCANNER_V4 controls origin-column visibility in page-level tables.

Changes

CVE origin support

Layer / File(s) Summary
Origin mapping and documentation
ui/apps/platform/src/Containers/Vulnerabilities/utils/vulnerabilityUtils.ts, ui/apps/platform/src/Containers/Vulnerabilities/utils/vulnerabilityUtils.test.ts, ui/apps/platform/src/Containers/Vulnerabilities/WorkloadCves/Tables/infoForTh.tsx
Adds origin label mapping, aggregation behavior, tests, and versioned CVE origin information.
Table data and origin aggregation
ui/apps/platform/src/Containers/Vulnerabilities/WorkloadCves/Tables/table.utils.ts
Adds CVSS, score version, and origin fields to table data. Deployment rows aggregate component origins.
Deployment vulnerability tables
ui/apps/platform/src/Containers/Vulnerabilities/WorkloadCves/Tables/Deployment*
Adds CVE origin retrieval, headers, cells, tooltips, and Dockerfile-layer span updates.
Image vulnerability tables
ui/apps/platform/src/Containers/Vulnerabilities/WorkloadCves/Tables/Image*
Adds CVSS, severity, and CVE origin retrieval and rendering. Image rows aggregate component origins.
Feature-flag column wiring
ui/apps/platform/src/Containers/Vulnerabilities/WorkloadCves/Deployment/DeploymentPageVulnerabilities.tsx, ui/apps/platform/src/Containers/Vulnerabilities/WorkloadCves/Image/ImagePageVulnerabilities.tsx
Hides the origin column when ROX_SCANNER_V4 is disabled.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to e9c08

This feature-gated UI change has no identified merge-blocking correctness or operational risk at the current head and is merge-ready after normal checks.

Suggested reviewers: alanonthegit, alwayshooin, bradr5

Sequence Diagram(s)

sequenceDiagram
  participant VulnerabilityGraphQL
  participant tableUtils
  participant VulnerabilityTable
  participant PageFeatureFlags
  VulnerabilityGraphQL->>tableUtils: Return CVSS, scoreVersion, and origin
  tableUtils->>tableUtils: Aggregate and format origin values
  tableUtils->>VulnerabilityTable: Provide vulnerability rows
  PageFeatureFlags->>VulnerabilityTable: Set origin-column visibility
  VulnerabilityTable->>VulnerabilityTable: Render CVE origin
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 7.14% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 10 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: adding CVE Origin UI support.
Description check ✅ Passed The description covers the change scope, feature-flag gating, documentation status, testing status, CI inspection, and manual validation with screenshots. It does not list every automated-test categor…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description covers the change scope, feature-flag gating, documentation status, testing status, CI inspection, and manual validation with screenshots. It does not list every automated-test category from the template, but the relevant testing information is sufficient.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dc/cve-origin-ui-display

Comment @coderabbitai help to get the list of available commands.

@dcaravel dcaravel changed the title ROX-35970: Add UI CVE Origin + Severity and CVSS to image components ROX-35970: Add CVE Origin UI Aug 26, 2026
@github-actions

github-actions Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Build Images Ready

Images are ready for commit f3f3b37. To use with deploy scripts:

export MAIN_IMAGE_TAG=5.0.x-92-gf3f3b37bba

@dcaravel
dcaravel marked this pull request as ready for review August 26, 2026 02:35
@dcaravel
dcaravel requested a review from a team as a code owner August 26, 2026 02:35
@dcaravel
dcaravel requested a review from dvail August 26, 2026 02:35
@codecov

codecov Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 51.30%. Comparing base (df7fd00) to head (e9c0856).
⚠️ Report is 25 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #22464      +/-   ##
==========================================
- Coverage   51.42%   51.30%   -0.12%     
==========================================
  Files        2869     2871       +2     
  Lines      179875   179881       +6     
==========================================
- Hits        92492    92286     -206     
- Misses      79286    79502     +216     
+ Partials     8097     8093       -4     
Flag Coverage Δ
go-unit-tests 51.30% <ø> (-0.12%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dcaravel

Copy link
Copy Markdown
Collaborator Author

/retest

@dvail dvail left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two comments, mostly nits and non-blocking. LGTM!

Comment thread ui/apps/platform/src/Containers/Vulnerabilities/utils/vulnerabilityUtils.ts Outdated
@dcaravel dcaravel added the auto-retest PRs with this label will be automatically retested if prow checks fails label Aug 26, 2026
@dcaravel
dcaravel merged commit f3f3b37 into master Aug 26, 2026
114 of 115 checks passed
@dcaravel
dcaravel deleted the dc/cve-origin-ui-display branch August 26, 2026 22:20
@dcaravel dcaravel mentioned this pull request Aug 26, 2026
4 tasks done
charmik-redhat pushed a commit that referenced this pull request Aug 27, 2026
dcaravel added a commit that referenced this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ui auto-retest PRs with this label will be automatically retested if prow checks fails

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants