Skip to content

Fix gitlab schema for glsca report(AST-180720) - #1581

Open
cx-sumit-morchhale wants to merge 3 commits into
mainfrom
bug/AST-180720-gitlab-schema-valid
Open

cx-sumit-morchhale wants to merge 3 commits into
mainfrom
bug/AST-180720-gitlab-schema-valid

Conversation

@cx-sumit-morchhale

Copy link
Copy Markdown
Contributor

Fixes GitLab schema validation failures (missing required keys: identifiers) on GL-SCA (dependency-scanning) reports. When a CVE has no advisory/reference data yet (e.g. very recently disclosed CVEs), collectScaPackageData() returned an empty identifiers slice, and the omitempty tag on GlScaDepVulnerabilities.Identifiers caused the JSON key to be dropped entirely which violates GitLab's schema requirement of at least one identifier per vulnerability (minItems: 1). GitLab then silently discards those findings from the Security Dashboard / Vulnerability Report.

# Please enter a commit message to explain why this merge is necessary,
# especially if it merges an updated upstream into a topic branch.
#
# Lines starting with '#' will be ignored, and an empty message aborts
# the commit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants