Skip to content

fix: Fix SSC SAST-DAST correlation state handling - #1105

Merged
rsenden merged 3 commits into
fortify:feat/v3.x/aviator/26.4from
ankit2995:ankit/correlation-bug-fix
Sep 23, 2026
Merged

rsenden merged 3 commits into
fortify:feat/v3.x/aviator/26.4from
ankit2995:ankit/correlation-bug-fix

Conversation

@ankit2995

Copy link
Copy Markdown
Contributor
  • Fixed negative and inaccurate SAST-DAST correlation counters.
  • Used SSC’s current merged state for suppression and eligibility decisions.
  • Uploads one mixed FPR only when correlation produces changes.
  • Skips gRPC processing and upload when scans are unchanged.
  • Reused shared SSC refresh, transfer, processing-wait, and cleanup logic across correlation and audit commands.
  • Added focused regression tests for correlation history, unchanged artifacts, link preservation, and previously tried pairs.

@ankit2995 ankit2995 changed the title Fix SSC SAST-DAST correlation state handling fix: Fix SSC SAST-DAST correlation state handling Sep 23, 2026
@ankit2995
ankit2995 marked this pull request as ready for review September 23, 2026 06:50
@ankit2995
ankit2995 requested a review from rsenden September 23, 2026 06:51
List<CorrelatedPair> rejectedPairs,
int receivedCorrelationResponses
) {}
int submittedCorrelationRequests,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider using Lombok @Builder to avoid potential incorrect order of the multiple int constructor args.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added Lombok @builder to CorrelationResult and replaced positional constructors.

return buildOutputJson(av, artifactId, submitted, succeeded, skipped, failed, newPairs, actionResult, null);
}

public static ObjectNode buildOutputJson(SSCAppVersionDescriptor av,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Too many method arguments; maybe introduce a separate data object or builder-like pattern, for example having a class like AviatorSSCCorrelateResultBuilder with fluent setters for the individual data elements, and a method to generate output json that uses the stored data, instead of receiving all data through long list of method args.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added builder-backed AviatorSSCCorrelateOutput, removing long output method argument lists.

return getUploadedArtifactId(uploadResponse);
}

public static void waitForArtifactProcessing(UnirestInstance unirest, String artifactId) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this method used anywhere? Quick find didn't show any references. If it is used, I have doubts about the hardcoded interval & time-out.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed unused waitForArtifactProcessing() and hardcoded timing values.

@ankit2995
ankit2995 requested a review from rsenden September 23, 2026 09:48
@rsenden
rsenden merged commit b54fb50 into fortify:feat/v3.x/aviator/26.4 Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants