[WIP] ROX-31850: Fix cve first occurance time policy and search criteria#19261
Open
[WIP] ROX-31850: Fix cve first occurance time policy and search criteria#19261
Conversation
Resolved migration number conflict by renumbering migration: - Master added m_220_to_m_221_add_deployment_hash_column - This branch's m_220_to_m_221_backfill_image_cve_infos_from_image_cves_v2 was renumbered to m_221_to_m_222_backfill_image_cve_infos_from_image_cves_v2 Updated package names, imports, and sequence numbers in: - migration.go: package m221tom222, startSeqNum = 221 - migration_impl.go: package and schema import path - migration_test.go: package and schema import path - all.go: includes both migrations in correct order Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
Contributor
|
Images are ready for the commit at 6e78700. To use with deploy scripts, first |
|
@c-du: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
First, the fix is primarily from ROX-31575 by adding and maintaining the image_cve_infos table with first_system_occurrence which record the first discovered time for cve#package#datasource.
This PR is to complete the solution by:
We also remove the hash:ignore tag to the createAt in the database. It was there to avoid frequent update to the vulns in database. With the fix to the logic, the createAt was updated before we upsert the image. The value is very stable and we should remove the hash tag to keep the data correct.
User-facing documentation
Testing and quality
Automated testing
How I validated my change
change me!