Backmerge dev/v3.x into Aviator 26.4 - #1107
Conversation
feat: `fcli fod session login`: Add `--code` and `--totp` options to support MFA-based logins (resolves fortify#1059)
feat: `fcli aviator ssc audit`: Add `--source-encodings` option for source decoding and audit skip reporting feat: `fcli aviator ssc apply-remediations`: Add `--source-encodings` option for source file decoding and encoding feat: `fcli fod aviator apply-remediations`: Add `--source-encodings` option for source file decoding and encoding Co-authored-by: Ankit Rathod <arathod3@opentext.com>
fix: `fcli fod dast-scan start`: Restore fix to allow DAST scan to start if no prior scans exist (lost in Aviator 26.2 merge) (fixes fortify#1068) fix: `fcli fod dast-scan start`: Restore `--vpn` support and 422 active-scan fallback (lost in Aviator 26.2 merge) fix: `fcli fod microservice create`: Re-add non-microservice application guard (lost in Aviator 26.2 merge)
feat: `fcli fod issue get`: New command for retrieving issue data for a single issue feat: `fcli ssc issue get`: New command for retrieving issue data for a single issue
feat: `fcli ai-assist mcp start-stdio`: Add `--server-name` option to configure custom MCP server name, defaulting to either `fcli-<module>` or `fcli` (depending on whether `--module` is specified)
…--rel/v3.x chore(rel/v3.x): release 3.24.0
…y#1082) feat: `fcli aviator ssc audit`: Add `--force-reaudit` to re-audit Aviator-processed issues without overwriting human triage fix: `fcli aviator ssc apply-remediations`: Skip remediations when source context matches multiple locations
…y#1084) Co-authored-by: Ankit Rathod <arathod3@opentext.com>
…--rel/v3.x chore(rel/v3.x): release 3.25.0
fix: `fcli aviator ssc apply-remediations`: More accurate application of auto-remediations fix: `fcli aviator ssc apply-remediations`: Improve handling of overlapping remediations fix: `fcli fod aviator apply-remediations`: More accurate application of auto-remediations fix: `fcli fod aviator apply-remediations`: Improve handling of overlapping remediations Co-authored-by: Umadevi Santhanam <usanthanam@opentext.com> Co-authored-by: Frans van Buul <fvbuul@opentext.com>
… users (fortify#1090) fix: `fcli ssc ac create-local-user`: The `--roles` option now properly accepts role names as per option description fix: `fcli ssc ac update-local-user`: The `--roles`, `--add-roles`, and `--rm-roles` options now properly accept role names as per option description
fix: `fcli aviator ssc apply-remediations`: Improve handling of non-writable files fix: `fcli fod aviator apply-remediations`: Improve handling of non-writable files Co-authored-by: Umadevi Santhanam <usanthanam@opentext.com>
…, XXE, Command Injection (fortify#1096) fix: Various MCP & Aviator security fixes
feat: SSC `ci` action: Add support for running DAST scans using existing DAST settings in SSC, and optionally waiting for DAST scan completion
…flow (fortify#1091) fix: `fcli fod`: Change id fields from `int` to `long` to avoid potential integer overflows
…--rel/v3.x chore(rel/v3.x): release 3.26.0
…ance (fortify#1103) fix: Skip unused FoD vulnerability filters for large-tenant performance
…--rel/v3.x chore(rel/v3.x): release 3.26.1
…1106) fix: `fcli aviator`: Improve log masking fix: `fcli tool`: Validate version strings
feat: `fod sast-scan start`: Add `--scan-policy` option to allow for specifying scan policy fix: `fod sast-scan start`: Don't override existing scan policy if `--scan-policy` is not supplied (fixes fortify#1095) Co-authored-by: kadraman <klee2@opentext.com>
…ations Keep the upstream/dev/v3.x applier and comparisonCode classification. Preview reports LineFrom, LineTo, OriginalCode, NewCode, and Context from remediations.xml without fuzzy matching or writing source files.
Preview no longer prints available, skipped, skipReason, or fuzzyMatched. Those values were leftovers from the old dry-run.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It is a large backmerge that reintegrates the remediation apply engine and many cross-module features, so byte-for-byte apply equivalence and preview behavior need human verification.
Review effort: Balanced
Findings: 1
What changed in this PR
This PR is a backmerge that brings the Aviator 26.4 feature set onto the vetted dev/v3.x remediation apply engine. The dev/v3.x apply pipeline (classifier/writer/rollback) is kept as-is, and three 26.4 features (--preview, --issue-ids, --from-cache) are reattached around it. It also carries along other 26.4 work: SSC/FoD remediations-cache download, SAST/DAST bulk-audit actions, SAST‑DAST correlation updates, and connection diagnostics.
Changes:
- Reattach
--preview(dump ofremediations.xmlfields only, no fuzzy-match/write),--issue-ids(requires--from-cache), and--from-cache(opensaudit.fvdlviaFprHandle) onto thedev/v3.xapply engine, including a new FoD download-remediations-cache command and shared FPR-source abstraction. - Replace the hardcoded
last_correlationattribute GUID inbulkcorrelate.yamlwith a dynamic attribute-definition lookup (by name/category/type) plus a warning when the definition is missing. - Add SSC/FoD helper methods and tests (Aviator-artifact detection, download-cache command arg validation) and parameterize the SSC bulk-audit validation spec across
bulkaudit-sast/bulkaudit/bulkaudit-dast.
| File | Description |
|---|---|
.../ftest/ssc/SSCAviatorAuditValidationSpec.groovy |
Parameterizes the quota/priority rejection test and adds bulkaudit-dast app-mapping/max-audits validation cases. |
.../ssc/artifact/helper/SSCArtifactHelperTest.java |
New unit tests for isAviatorArtifact/requireAviatorArtifact. |
.../ssc/actions/zip/ci.yaml |
Removes trailing whitespace on a blank line (no behavior change). |
.../ssc/actions/zip/bulkcorrelate.yaml |
Dynamic last_correlation attribute-definition lookup replacing a hardcoded GUID, with a missing-definition warning. |
.../ssc/artifact/helper/SSCArtifactHelper.java |
Adds public isAviatorArtifact(descriptor) and requireAviatorArtifact(descriptor). |
.../fod/aviator/FoDAviatorDownloadRemediationsCacheCommandTest.java |
New tests asserting --release and -f/--file are required. |
.../fod/i18n/FoDMessages.properties |
Adds apply-remediations/download-cache descriptions and identicalRemediation output column. |
.../fod/aviator/helper/FoDOnlineRemediationsFprSource.java |
New online FPR source that downloads the release FPR to a managed temp file per entry. |
.../fod/aviator/cmd/FoDAviatorCommands.java |
Registers the new download-remediations-cache subcommand. |
.../fod/aviator/cli/mixin/FoDAviatorApplyRemediationsOptionsMixin.java |
New mixin combining online/--from-cache source selection with shared apply options. |
.../fpr/processor/preview/{FilePreview,PreviewDetail,ContextMetadata,FileChange}Test.java |
New preview DTO tests; misplaced directory vs. declared package and duplicate PreviewDtoTest coverage (see comment). |
Note: this is a large backmerge and only a subset of the ~90 changed files was directly inspected; the summary above reflects the reviewed portions.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| * herein. The information contained herein is subject to change | ||
| * without notice. | ||
| */ | ||
| package com.fortify.cli.aviator.fpr.remediation.preview; |
The processor/preview classes declared the remediation.preview package. PreviewDtoTest already covers those constructors.
A preview of an FPR with no remediations.xml skipped the artifact before any metric existed, so the empty result was reported as apply. The requested execution mode is now kept on that empty result.
Online apply and download-remediations-cache both walk --all newest first. The help text and the order-test comment now match that behavior.
|
Verified all the code in PR 1089 is present in this PR. |
8c28787
into
fortify:feat/v3.x/aviator/26.4

Summary
Merges current
dev/v3.xintofeat/v3.x/aviator/26.4.Remediation processing had diverged.
dev/v3.xhas the vetted apply engine (split applier, classifier, writer). 26.4 still had the older processor, plus--preview,--issue-ids, and--from-cache. This branch keeps the vetted engine and reattaches those three features around it. The rest of the diff isdev/v3.xhistory that 26.4 does not have yet, through 3.26.1.Apply stays the vetted
dev/v3.xengineUnfiltered apply classifies and writes the same way as
dev/v3.x:dev/v3.xRemediationApplier. Those files matchdev/v3.x.comparisonCode(all whitespace removed), notlineNormalizedCode. A nested multi-line match stays possibly-remediated. Both of those outcomes skip the write, so the source bytes followdev/v3.x.--allstill applies newest-first.getAllAviatorArtifactsstays oldest-first, and the shared resolver reverses that list once.Critical 26.4 wiring
--previewdoes not run the applier. It lists the declaredremediations.xmlfields:LineFrom,LineTo,OriginalCode,NewCode, andContext. It does not fuzzy-match and it does not write source files. A missing source file is still reported as skipped.available,skipped, andskipReasonare gone. Per change,fuzzyMatchedis gone (it was always false once preview stopped searching).statusremainsavailableorskipped. Skip-reason text stays on the summary fieldskippedReasons.--issue-idsstill filters. An empty filter processes every remediation, same asdev/v3.x.--from-cacheopensaudit.fvdlthroughFprHandle. The load isFiles.newInputStream(fprHandle.getPath("/audit.fvdl")), notZipFile(path.toFile()).toFile()fails when the FPR is an entry inside the remediations cache zip, and a failed encoding load skips remediations. This is the one apply-path I/O difference fromdev/v3.x.Review focus
Please check that unfiltered apply still writes the same bytes as
dev/v3.x, and that--previewis only a dump ofremediations.xml.