fix: Fix SSC SAST-DAST correlation state handling - #1105
Conversation
ankit2995
commented
Sep 23, 2026
- Fixed negative and inaccurate SAST-DAST correlation counters.
- Used SSC’s current merged state for suppression and eligibility decisions.
- Uploads one mixed FPR only when correlation produces changes.
- Skips gRPC processing and upload when scans are unchanged.
- Reused shared SSC refresh, transfer, processing-wait, and cleanup logic across correlation and audit commands.
- Added focused regression tests for correlation history, unchanged artifacts, link preservation, and previously tried pairs.
| List<CorrelatedPair> rejectedPairs, | ||
| int receivedCorrelationResponses | ||
| ) {} | ||
| int submittedCorrelationRequests, |
There was a problem hiding this comment.
Consider using Lombok @Builder to avoid potential incorrect order of the multiple int constructor args.
There was a problem hiding this comment.
Added Lombok @builder to CorrelationResult and replaced positional constructors.
| return buildOutputJson(av, artifactId, submitted, succeeded, skipped, failed, newPairs, actionResult, null); | ||
| } | ||
|
|
||
| public static ObjectNode buildOutputJson(SSCAppVersionDescriptor av, |
There was a problem hiding this comment.
Too many method arguments; maybe introduce a separate data object or builder-like pattern, for example having a class like AviatorSSCCorrelateResultBuilder with fluent setters for the individual data elements, and a method to generate output json that uses the stored data, instead of receiving all data through long list of method args.
There was a problem hiding this comment.
Added builder-backed AviatorSSCCorrelateOutput, removing long output method argument lists.
| return getUploadedArtifactId(uploadResponse); | ||
| } | ||
|
|
||
| public static void waitForArtifactProcessing(UnirestInstance unirest, String artifactId) { |
There was a problem hiding this comment.
Is this method used anywhere? Quick find didn't show any references. If it is used, I have doubts about the hardcoded interval & time-out.
There was a problem hiding this comment.
Removed unused waitForArtifactProcessing() and hardcoded timing values.