Skip to content

fix: convert FoD identifier fields from int to long to prevent overflow - #1091

Merged
rsenden merged 5 commits into
fortify:dev/v3.xfrom
jmadhur87:mjain6/fod-id-int-to-long-migration
Sep 18, 2026
Merged

rsenden merged 5 commits into
fortify:dev/v3.xfrom
jmadhur87:mjain6/fod-id-int-to-long-migration

Conversation

@jmadhur87

Copy link
Copy Markdown
Contributor

Fixes potential overflow bugs in FoD identifier handling. Several FoD IDs (report, release, user, group, attribute, scan, entitlement) were stored as Integer/int, which breaks once an ID grows past ~2.1 billion. Converted them to long.

Affects several commands: release update/create (--owner/--app-owner), app create (--owner), issue update (--user), group/user update (--add-users/--remove-users/--add-groups/--remove-groups), sast/mast/dast-scan setup/start (--entitlement-id), attribute and report get/update/delete (--attribute-id/--report-id), plus output field types on several list/get commands.

@jmadhur87
jmadhur87 marked this pull request as ready for review September 7, 2026 05:41
@jmadhur87
jmadhur87 requested review from kadraman and rsenden and removed request for rsenden September 7, 2026 15:00

@rsenden rsenden left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this looks mostly fine, just wondering though why you changed FoDAppDescriptor::applicationId from String to Long, whereas you didn't do the same for FoDReleaseDescriptor::applicatonId, nor for the releaseId and microserviceId fields in the various descriptors.

Please ensure we're using a consistent approach for these id's; either treat them all as strings, or treat them all as longs.

@jmadhur87
jmadhur87 force-pushed the mjain6/fod-id-int-to-long-migration branch from e19bb8d to dbc0cae Compare September 18, 2026 11:24
@jmadhur87

Copy link
Copy Markdown
Contributor Author

@rsenden For consistency, reverted the applicationId from long to string.

@jmadhur87
jmadhur87 requested a review from rsenden September 18, 2026 11:41
@rsenden
rsenden merged commit 93f166d into fortify:dev/v3.x Sep 18, 2026
14 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants