Skip to content

Backmerge dev/v3.x into Aviator 26.4 - #1107

Merged
rsenden merged 43 commits into
fortify:feat/v3.x/aviator/26.4from
kireetivar:p/kireetivar/backmerge
Sep 28, 2026
Merged

rsenden merged 43 commits into
fortify:feat/v3.x/aviator/26.4from
kireetivar:p/kireetivar/backmerge

Conversation

@kireetivar

@kireetivar kireetivar commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Merges current dev/v3.x into feat/v3.x/aviator/26.4.

Remediation processing had diverged. dev/v3.x has the vetted apply engine (split applier, classifier, writer). 26.4 still had the older processor, plus --preview, --issue-ids, and --from-cache. This branch keeps the vetted engine and reattaches those three features around it. The rest of the diff is dev/v3.x history that 26.4 does not have yet, through 3.26.1.

Apply stays the vetted dev/v3.x engine

Unfiltered apply classifies and writes the same way as dev/v3.x:

  • Hash match, offset projection, fuzzy anchor, NewCode splice, all-or-nothing commit, and rollback are the dev/v3.x RemediationApplier. Those files match dev/v3.x.
  • Nested-hunk classification still passes comparisonCode (all whitespace removed), not lineNormalizedCode. A nested multi-line match stays possibly-remediated. Both of those outcomes skip the write, so the source bytes follow dev/v3.x.
  • --all still applies newest-first. getAllAviatorArtifacts stays oldest-first, and the shared resolver reverses that list once.

Critical 26.4 wiring

  • --preview does not run the applier. It lists the declared remediations.xml fields: LineFrom, LineTo, OriginalCode, NewCode, and Context. It does not fuzzy-match and it does not write source files. A missing source file is still reported as skipped.
  • Preview JSON dropped the old dry-run fields. Per issue, available, skipped, and skipReason are gone. Per change, fuzzyMatched is gone (it was always false once preview stopped searching). status remains available or skipped. Skip-reason text stays on the summary field skippedReasons.
  • --issue-ids still filters. An empty filter processes every remediation, same as dev/v3.x.
  • --from-cache opens audit.fvdl through FprHandle. The load is Files.newInputStream(fprHandle.getPath("/audit.fvdl")), not ZipFile(path.toFile()). toFile() fails when the FPR is an entry inside the remediations cache zip, and a failed encoding load skips remediations. This is the one apply-path I/O difference from dev/v3.x.

Review focus

Please check that unfiltered apply still writes the same bytes as dev/v3.x, and that --preview is only a dump of remediations.xml.

SangameshV and others added 30 commits August 20, 2026 18:24
feat: `fcli fod session login`: Add `--code` and `--totp` options to support MFA-based logins (resolves fortify#1059)
feat: `fcli aviator ssc audit`: Add `--source-encodings` option for source decoding and audit skip reporting

feat: `fcli aviator ssc apply-remediations`: Add `--source-encodings` option for source file decoding and encoding

feat: `fcli fod aviator apply-remediations`: Add `--source-encodings` option for source file decoding and encoding

Co-authored-by: Ankit Rathod <arathod3@opentext.com>
fix: `fcli fod dast-scan start`: Restore fix to allow DAST scan to start if no prior scans exist (lost in Aviator 26.2 merge) (fixes fortify#1068)

fix: `fcli fod dast-scan start`: Restore  `--vpn` support and 422 active-scan fallback (lost in Aviator 26.2 merge)

fix: `fcli fod microservice create`: Re-add non-microservice application guard (lost in Aviator 26.2 merge)
feat: `fcli fod issue get`: New command for retrieving issue data for a single issue

feat: `fcli ssc issue get`: New command for retrieving issue data for a single issue
feat: `fcli ai-assist mcp start-stdio`: Add `--server-name` option to configure custom MCP server name, defaulting to either `fcli-<module>` or `fcli` (depending on whether `--module` is specified)
…--rel/v3.x

chore(rel/v3.x): release 3.24.0
…y#1082)

feat: `fcli aviator ssc audit`: Add `--force-reaudit` to re-audit Aviator-processed issues without overwriting human triage

fix: `fcli aviator ssc apply-remediations`: Skip remediations when source context matches multiple locations
…y#1084)

Co-authored-by: Ankit Rathod <arathod3@opentext.com>
…--rel/v3.x

chore(rel/v3.x): release 3.25.0
fix: `fcli aviator ssc apply-remediations`: More accurate application of auto-remediations

fix: `fcli aviator ssc apply-remediations`: Improve handling of overlapping remediations

fix: `fcli fod aviator apply-remediations`: More accurate application of auto-remediations

fix: `fcli fod aviator apply-remediations`: Improve handling of overlapping remediations

Co-authored-by: Umadevi Santhanam <usanthanam@opentext.com>

Co-authored-by: Frans van Buul <fvbuul@opentext.com>
… users (fortify#1090)

fix: `fcli ssc ac create-local-user`: The `--roles` option now properly accepts role names as per option description

fix: `fcli ssc ac update-local-user`: The `--roles`, `--add-roles`, and `--rm-roles` options now properly accept role names as per option description
fix: `fcli aviator ssc apply-remediations`: Improve handling of non-writable files

fix: `fcli fod aviator apply-remediations`: Improve handling of non-writable files

Co-authored-by: Umadevi Santhanam <usanthanam@opentext.com>
…, XXE, Command Injection (fortify#1096)

fix: Various MCP & Aviator security fixes
feat: SSC `ci` action: Add support for running DAST scans using existing DAST settings in SSC, and optionally waiting for DAST scan completion
…flow (fortify#1091)

fix: `fcli fod`: Change id fields from `int` to `long` to avoid potential integer overflows
…--rel/v3.x

chore(rel/v3.x): release 3.26.0
…ance (fortify#1103)

fix: Skip unused FoD vulnerability filters for large-tenant performance
github-actions Bot and others added 9 commits September 22, 2026 13:24
…--rel/v3.x

chore(rel/v3.x): release 3.26.1
…1106)

fix: `fcli aviator`: Improve log masking

fix: `fcli tool`: Validate version strings
feat: `fod sast-scan start`: Add `--scan-policy` option to allow for specifying scan policy

fix: `fod sast-scan start`: Don't override existing scan policy if `--scan-policy` is not supplied (fixes fortify#1095)

Co-authored-by: kadraman <klee2@opentext.com>
…ations

Keep the upstream/dev/v3.x applier and comparisonCode classification.
Preview reports LineFrom, LineTo, OriginalCode, NewCode, and Context
from remediations.xml without fuzzy matching or writing source files.
Preview no longer prints available, skipped, skipReason, or fuzzyMatched.
Those values were leftovers from the old dry-run.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It is a large backmerge that reintegrates the remediation apply engine and many cross-module features, so byte-for-byte apply equivalence and preview behavior need human verification.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR is a backmerge that brings the Aviator 26.4 feature set onto the vetted dev/v3.x remediation apply engine. The dev/v3.x apply pipeline (classifier/writer/rollback) is kept as-is, and three 26.4 features (--preview, --issue-ids, --from-cache) are reattached around it. It also carries along other 26.4 work: SSC/FoD remediations-cache download, SAST/DAST bulk-audit actions, SAST‑DAST correlation updates, and connection diagnostics.

Changes:

  • Reattach --preview (dump of remediations.xml fields only, no fuzzy-match/write), --issue-ids (requires --from-cache), and --from-cache (opens audit.fvdl via FprHandle) onto the dev/v3.x apply engine, including a new FoD download-remediations-cache command and shared FPR-source abstraction.
  • Replace the hardcoded last_correlation attribute GUID in bulkcorrelate.yaml with a dynamic attribute-definition lookup (by name/category/type) plus a warning when the definition is missing.
  • Add SSC/FoD helper methods and tests (Aviator-artifact detection, download-cache command arg validation) and parameterize the SSC bulk-audit validation spec across bulkaudit-sast/bulkaudit/bulkaudit-dast.
File Description
.../​ftest/​ssc/​SSCAviatorAuditValidationSpec.groovy Parameterizes the quota/priority rejection test and adds bulkaudit-dast app-mapping/max-audits validation cases.
.../​ssc/​artifact/​helper/​SSCArtifactHelperTest.java New unit tests for isAviatorArtifact/requireAviatorArtifact.
.../​ssc/​actions/​zip/​ci.yaml Removes trailing whitespace on a blank line (no behavior change).
.../​ssc/​actions/​zip/​bulkcorrelate.yaml Dynamic last_correlation attribute-definition lookup replacing a hardcoded GUID, with a missing-definition warning.
.../​ssc/​artifact/​helper/​SSCArtifactHelper.java Adds public isAviatorArtifact(descriptor) and requireAviatorArtifact(descriptor).
.../​fod/​aviator/​FoDAviatorDownloadRemediationsCacheCommandTest.java New tests asserting --release and -f/--file are required.
.../​fod/​i18n/​FoDMessages.properties Adds apply-remediations/download-cache descriptions and identicalRemediation output column.
.../​fod/​aviator/​helper/​FoDOnlineRemediationsFprSource.java New online FPR source that downloads the release FPR to a managed temp file per entry.
.../​fod/​aviator/​cmd/​FoDAviatorCommands.java Registers the new download-remediations-cache subcommand.
.../​fod/​aviator/​cli/​mixin/​FoDAviatorApplyRemediationsOptionsMixin.java New mixin combining online/--from-cache source selection with shared apply options.
.../​fpr/​processor/​preview/​{FilePreview,PreviewDetail,ContextMetadata,FileChange}Test.java New preview DTO tests; misplaced directory vs. declared package and duplicate PreviewDtoTest coverage (see comment).

Note: this is a large backmerge and only a subset of the ~90 changed files was directly inspected; the summary above reflects the reviewed portions.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

* herein. The information contained herein is subject to change
* without notice.
*/
package com.fortify.cli.aviator.fpr.remediation.preview;
The processor/preview classes declared the remediation.preview package.
PreviewDtoTest already covers those constructors.
@kireetivar
kireetivar changed the base branch from dev/v3.x to feat/v3.x/aviator/26.4 September 24, 2026 13:46
@kireetivar kireetivar self-assigned this Sep 24, 2026
A preview of an FPR with no remediations.xml skipped the artifact before
any metric existed, so the empty result was reported as apply. The
requested execution mode is now kept on that empty result.
Online apply and download-remediations-cache both walk --all newest first.
The help text and the order-test comment now match that behavior.
@kireetivar
kireetivar marked this pull request as ready for review September 24, 2026 17:45
@umadevis1

Copy link
Copy Markdown
Contributor

Verified all the code in PR 1089 is present in this PR.

@rsenden
rsenden merged commit 8c28787 into fortify:feat/v3.x/aviator/26.4 Sep 28, 2026
14 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants