ROX-35970: Add CVE Origin UI - #22464
Conversation
|
Skipping CI for Draft Pull Request. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited) Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughSummary by CodeRabbit
WalkthroughThe vulnerability tables now retrieve CVSS, score version, and CVE origin data. They render origin values for image and deployment vulnerabilities. ChangesCVE origin support
Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk: ⚪ Minimal · up to This feature-gated UI change has no identified merge-blocking correctness or operational risk at the current head and is merge-ready after normal checks. Suggested reviewers: Sequence Diagram(s)sequenceDiagram
participant VulnerabilityGraphQL
participant tableUtils
participant VulnerabilityTable
participant PageFeatureFlags
VulnerabilityGraphQL->>tableUtils: Return CVSS, scoreVersion, and origin
tableUtils->>tableUtils: Aggregate and format origin values
tableUtils->>VulnerabilityTable: Provide vulnerability rows
PageFeatureFlags->>VulnerabilityTable: Set origin-column visibility
VulnerabilityTable->>VulnerabilityTable: Render CVE origin
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Description checkExplanation The description covers the change scope, feature-flag gating, documentation status, testing status, CI inspection, and manual validation with screenshots. It does not list every automated-test category from the template, but the relevant testing information is sufficient.
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
🚀 Build Images ReadyImages are ready for commit f3f3b37. To use with deploy scripts: export MAIN_IMAGE_TAG=5.0.x-92-gf3f3b37bba |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #22464 +/- ##
==========================================
- Coverage 51.42% 51.30% -0.12%
==========================================
Files 2869 2871 +2
Lines 179875 179881 +6
==========================================
- Hits 92492 92286 -206
- Misses 79286 79502 +216
+ Partials 8097 8093 -4
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
/retest |
dvail
left a comment
There was a problem hiding this comment.
Two comments, mostly nits and non-blocking. LGTM!
Description
Adds new CVE Origin field to the single image and deployment pages. The field is added to the aggregate CVE rows as well as individual component rows.
Also adds severity and CVSS columns to the image component rows.
The origin field is conditional on Scanner V4 being enabled (similar to EPSS).
User-facing documentation
Testing and quality
Automated testing
How I validated my change
CI + Manual testing
Image page:
Deployment Page:
Info Popover:
CVE Origin column is hidden when Scanner V4 Disabled: