Skip to content

fix(worker): forward affected_url and description from findings - #643

Merged
l1ttps merged 2 commits into
mainfrom
fix/worker-affected-url-description
Sep 20, 2026
Merged

l1ttps merged 2 commits into
mainfrom
fix/worker-affected-url-description

Conversation

@l1ttps

@l1ttps l1ttps commented Sep 19, 2026

Copy link
Copy Markdown
Member

What

  • Map Finding.MatchedAt → Vulnerability.affected_url in findingToVulnerability. Previously matched_at was dropped, so the vulnerabilities.affectedUrl column was always empty.
  • Map the new Finding.Description → Vulnerability.description.
  • Regenerate the connector proto stubs (Finding.description = 15) and the source proto to stay in sync with the SDK.

Why

Connector findings carried the affected URL (as MatchedAt) and, after the SDK change, a description, but the worker discarded both before submitting to Core.

Testing

  • task worker:test — pass
  • task worker:lint / task worker:check — pass
  • job_connector_test.go asserts the matched_at → affected_url and description mappings.

Companion SDK/connector changes: oasm-platform/oasm-connectors (branch develop).

findingToVulnerability dropped matched_at, so Vulnerability.affected_url
was always empty; map Finding.MatchedAt onto it. Also forward the new
Finding.Description onto Vulnerability.description and regenerate the
connector proto stubs.
@l1ttps
l1ttps merged commit eea88fb into main Sep 20, 2026
20 of 21 checks passed
@l1ttps
l1ttps deleted the fix/worker-affected-url-description branch September 20, 2026 04:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant