You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Fix package and risk acceptance filtering (#97)
* fix: regression on filter by package in action summary
* Add test for accepted risk filter in summary
* Add test for severity filter in summary report
* Fix vulnerability counts in summary report
* Fix accepted risk filtering logic
Refine filtering logic to correctly handle risk acceptance at the vulnerability level versus package level.
1. Stopped associating accepted risks from vulnerabilities to their packages in the Sysdig adapter. This prevents the 'withoutAcceptedRisks' filter from discarding the entire package when only a specific vulnerability has an accepted risk.
2. Updated SummaryReportPresenter to explicitly filter out vulnerabilities with accepted risks when generating the report tables, ensuring that even if the package remains (due to other active vulnerabilities), the accepted ones are hidden/not counted.
* Add package level acceptance risks and tests
* Add message about applied filters in the summary
* Add details about filter in summary