Repository navigation
[CSM Portal] add product vulnerabilities list and detail view - #967
Conversation
|
Warning Review limit reached
More reviews will be available in 39 minutes and 15 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (8)
📝 WalkthroughWalkthroughAdds a product vulnerabilities feature to the Security Center: new backend DTOs for vulnerabilities and deployed products, two React Query hooks (single-fetch and search), a searchable/paginated Security Center Vulnerabilities Feature
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai full review |
✅ Action performedFull review finished. |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/csm-portal/webapp/src/api/backend/types.ts`:
- Around line 864-869: BeDeployedProductDetailUpdatePayload currently allows an
empty object even though the PATCH contract requires at least one of cores, tps,
or description. Update this type in types.ts to encode a non-empty/at-least-one
constraint using a union or utility type around
BeDeployedProductDetailUpdatePayload so that {} is rejected at compile time
while preserving the existing field types and active?: never exclusion.
In
`@apps/csm-portal/webapp/src/features/csm-security-center/components/ProductVulnerabilitiesTab.tsx`:
- Around line 135-169: The empty-state branch in ProductVulnerabilitiesTab
should not render when the query fails, because `isError` leaves
`vulnerabilities` empty and incorrectly shows “No vulnerabilities found.” Update
the conditional rendering around the `TableBody`/error alert so the error state
takes precedence and the empty-state row only appears when the query succeeded
with zero results. Also ensure the `total` used for pagination is derived from
successful data only, not from an error fallback.
- Around line 172-176: The TableRow click target in ProductVulnerabilitiesTab is
mouse-only, so keyboard users cannot open the vulnerability detail page. Update
the row interaction around the
navigate(`/security-center/vulnerabilities/${vuln.id}`) handler to use proper
link/button semantics via the TableRow or an inner interactive element, or add
focusability plus Enter/Space key handling if the row must remain clickable.
Ensure the interactive target is discoverable and operable from the keyboard
without changing the navigation behavior.
- Line 175: The navigation in ProductVulnerabilitiesTab’s onClick is using
vuln.id directly in the route, which can break for IDs containing reserved URL
characters. Update the route construction to URL-encode vuln.id before passing
it to navigate, and keep the client route segment aligned with the detail flow
that already encodes the backend path.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: db097e63-a466-4e9b-8151-d74f46d662df
📒 Files selected for processing (8)
apps/csm-portal/webapp/src/App.tsxapps/csm-portal/webapp/src/api/backend/types.tsapps/csm-portal/webapp/src/features/csm-security-center/api/useGetProductVulnerability.tsapps/csm-portal/webapp/src/features/csm-security-center/api/useSearchProductVulnerabilities.tsapps/csm-portal/webapp/src/features/csm-security-center/components/ProductVulnerabilitiesTab.tsxapps/csm-portal/webapp/src/features/csm-security-center/pages/CsmSecurityCenterPage.tsxapps/csm-portal/webapp/src/features/csm-security-center/pages/ProductVulnerabilityDetailPage.tsxapps/csm-portal/webapp/src/features/csm-security-center/utils/vulnerabilities.ts
4bab7ac to
ae4d543
Compare
Wire up the Vulnerabilities tab in Security Center (previously "coming
soon") with a server-side-paginated table (search + priority filter) and
a read-only detail page. Adds Be* types for the three new schemas, two
react-query hooks against the existing POST /products/vulnerabilities/search
and GET /products/vulnerabilities/{id} endpoints, priority colour/label
utils, and a lazy-loaded route under security-center/vulnerabilities/:id.
Migrates the tab selection to URL search params (?tab=) so the detail
page back-link lands on the correct tab.
ae4d543 to
d244329
Compare
Summary
Builds out the Security Center Vulnerabilities tab (previously a "coming soon" placeholder) against the now-available product-vulnerabilities endpoints. FE-only.
POST /products/vulnerabilities/search): debounced text search, priority filter, and columns for CVE / vulnerability id, component, product, priority, type, and update level.GET /products/vulnerabilities/{id}) atsecurity-center/vulnerabilities/:idshowing the scalar fields plus use case / justification / resolution when present.Implementation
Be*vulnerability types insrc/api/backend/types.ts; reuses the existingPRODUCT_VULNERABILITIES_SEARCH/PRODUCT_VULNERABILITYquery keys.keepPreviousData, null-on-missing).utils/vulnerabilities.ts; thepriorityfield is an upstream label, so the colour lookup is case-insensitive.?tab=vulnerabilities) so the detail page's back button lands on the right tab.Notes
useCase/justification/resolutionare rendered as plain (pre-wrapped) text since the spec types them as plain strings; if they turn out to carry ServiceNow rich-text HTML, that's a small follow-up to sanitize + render as HTML.Test plan
pnpm buildpassespnpm lintclean (one pre-existing unrelated warning)pnpm test— 104 passingSummary by CodeRabbit
New Features
Bug Fixes