Skip to content

ROX-37300: Backport CVE Origin display, reporting, and filtering - #23175

Open
dcaravel wants to merge 6 commits into
release-4.11from
dc/backport-osv-origin-backend-to-release-4.11
Open

dcaravel wants to merge 6 commits into
release-4.11from
dc/backport-osv-origin-backend-to-release-4.11

Conversation

@dcaravel

@dcaravel dcaravel commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Cherry picks the 3 back-end changes adding support for displaying, reporting, and filtering on CVE origin

And 3 related front-end changes:

Each commit in this backport aligns with the squashed / merge commits from master (after resolving merge conflicts)

Notes to reviewers:
There were merges conflicts with the CISA KEV additions that preceded each of these PRs (had to be removed from the backports) - in particular proto/storage/vulnerability.proto was modified to skip the numbers for the CISA KEV fields to keep the wire format compatible, please take a look and verify looks OK to you.

User-facing documentation

Testing and quality

  • the change is production ready: the change is GA, or otherwise the functionality is gated by a feature flag
  • CI results are inspected

Automated testing

  • added unit tests
  • modified existing tests

How I validated my change

Automated tests + manual tests are PENDING

Manual tests, both 4.11 and 5.1 versions of roxctl are able to parse origin field as expected against Central running version from this PR.

$ roxctl version
5.1.x-157-g21188e6c80

stackrox-backport-osv-origin-4.11 dc/backport-osv-origin-backend-to-release-4.11 ≡ 
$ roxctl image scan --image=quay.io/rhacs-eng/main:4.10.3 2>/dev/null | jq -r '.scan.components[]?.vulns[]?.origin' | sort | uniq -c | sort
 126 VULN_ORIGIN_OSV
 328 VULN_ORIGIN_RED_HAT
$ ./bin/darwin_arm64/roxctl version
4.11.5-rc.1-12-g07f7e280e0

$ ./bin/darwin_arm64/roxctl image scan --image=quay.io/rhacs-eng/main:4.10.3 2>/dev/null | jq -r '.scan.components[]?.vulns[]?.origin' | sort | uniq -c | sort
 126 VULN_ORIGIN_OSV
 328 VULN_ORIGIN_RED_HAT

Co-authored-by: StackRox PR Fixxxer <rhacs-bot@redhat.com>
(cherry picked from commit 2e1ca7e)
@openshift-ci

openshift-ci Bot commented Sep 30, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@github-actions github-actions Bot added area/central backport PR to backport changes from master to release branch labels Sep 30, 2026
@dcaravel dcaravel changed the title ROX-35509: Create and Populate Vuln Origin (#22335) WIP - ROX-35509: Create and Populate Vuln Origin (#22335) Sep 30, 2026
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Build Images Ready

Images are ready for commit 07f7e28. To use with deploy scripts:

export MAIN_IMAGE_TAG=4.11.5-rc.1-12-g07f7e280e0

@dcaravel dcaravel changed the title WIP - ROX-35509: Create and Populate Vuln Origin (#22335) ROX-35509: Backport CVE Origin display, reporting, and filtering Oct 1, 2026
@dcaravel dcaravel changed the title ROX-35509: Backport CVE Origin display, reporting, and filtering ROX-37300: Backport CVE Origin display, reporting, and filtering Oct 1, 2026
dcaravel and others added 3 commits October 1, 2026 15:14
…#22517)

"CVSS" and "CVE severity" column headings changed to "Top CVSS" and "Top CVE Severity" on pages where the values are aggregated.
@dcaravel

dcaravel commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator Author

Opening for review to get tests to run.

@dcaravel
dcaravel marked this pull request as ready for review October 1, 2026 20:17
@dcaravel
dcaravel requested review from a team as code owners October 1, 2026 20:17

@dvail dvail left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving UI changes on behalf of UI team based on review in #23129

@openshift-ci

openshift-ci Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

@dcaravel: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/gke-ui-e2e-tests 07f7e28 link false /test gke-ui-e2e-tests
ci/prow/ocp-4-12-ui-e2e-tests 07f7e28 link false /test ocp-4-12-ui-e2e-tests
ci/prow/ocp-4-22-ui-e2e-tests 07f7e28 link false /test ocp-4-22-ui-e2e-tests

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@dcaravel

dcaravel commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

/test ocp-4-12-operator-e2e-tests

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/central area/postgres area/ui backport PR to backport changes from master to release branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants