Skip to content

chore: Merge Aviator 26.4 changes - #1116

Draft
kireetivar wants to merge 93 commits into
dev/v3.xfrom
feat/v3.x/aviator/26.4
Draft

kireetivar wants to merge 93 commits into
dev/v3.xfrom
feat/v3.x/aviator/26.4

Conversation

@kireetivar

@kireetivar kireetivar commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
feat: `fcli aviator ssc audit-dast`: New command for auditing DAST findings in SSC
feat: `fcli aviator ssc audit-sast`: New SAST audit command. `audit` remains as a deprecated alias, and `bulkaudit` delegates to `bulkaudit-sast`
feat: `ssc bulkaudit-dast` action: Run Aviator DAST audit across SSC application versions
feat: `fcli aviator ssc download-remediations-cache`: Download audited FPRs into a remediations cache zip
feat: `fcli fod aviator download-remediations-cache`: Download the latest static audited FPR into a remediations cache zip
feat: `fcli aviator ssc apply-remediations`: Add `--from-cache` to apply remediations from a local cache zip
feat: `fcli fod aviator apply-remediations`: Add `--from-cache` to apply remediations from a local cache zip
feat: `fcli aviator ssc apply-remediations`: Add `--preview` to show declared remediations without changing source files
feat: `fcli aviator ssc apply-remediations`: Add `--issue-ids` to apply selected remediations
feat: `fcli fod aviator apply-remediations`: Add `--preview` to show declared remediations without changing source files
feat: `fcli fod aviator apply-remediations`: Add `--issue-ids` to apply selected remediations
feat: `fcli aviator connection diagnose`: Check Aviator gRPC connectivity and accept only HTTPS URLs
fix: `fcli aviator apply-remediations`: Compare overlapping remediations using the declared line range
fix: `fcli aviator ssc correlate-sast-dast`: Fix correlation state handling

Neeta Meshram and others added 30 commits April 16, 2026 12:04
…on and SSC upload

- Add correlate-sast-dast command for SSC Aviator
- Parse SAST (FVDL) and DAST (WebInspect) FPRs from SSC
- Group findings by category, identify mixed SAST+DAST buckets
- gRPC-based correlation stream with Aviator server
- Inject ExternalFindings into DAST FPR for SSC correlation visibility
- Upload enriched DAST FPR back to SSC
- Add streaming WebInspect parser for large DAST FPRs
- Add getLatestSASTArtifact/getLatestDASTArtifact helpers
- Add unit and integration tests for ExternalFindings injection flow
- Add correlation.proto for gRPC service definition
… upsert AI_CORRELATION_METADATA session

- Extract AviatorSSCCorrelateHelper, AviatorSSCCorrelateFprParser, AviatorSSCCorrelateDownloadHelper from command class to reduce GOD class
- Add proper try/catch(IOException) around FPR download calls
- Add progress logging at each major step (download, parse, group, correlate, inject, upload)
- Add per-response progress in CorrelationStreamProcessor (Correlating X of Y / Validating X of Y)
- Rename ExternalFindingsInjector to DastFprCorrelationEnricher to reflect full scope
- Upsert synthetic <Session requestId=AI_CORRELATION_METADATA> in webinspect.xml with HTTP Date header to avoid needing to delete prior DAST scan before re-upload
- Update references in test classes
…ied pairs, write last_correlation attribute

- Add CorrelationResult record to return both confirmed and rejected pairs from gRPC stream
- Track rejected pairs in CorrelationStreamState + CorrelationStreamProcessor
- Parse ExternalFindings from DAST FPR via StreamingWebInspectParser to build confirmed pair keys
- Add SastFprCorrelationRecorder: read/write DAST_CORRELATION_STATUS tag in SAST FPR audit.xml
  - Namespace-aware XML parsing (setNamespaceAware + getElementsByTagNameNS)
  - Creates new Issue elements for SAST findings with no prior audit record
  - Merge logic: CORRELATED is sticky, cannot be downgraded to REJECTED on re-run
- Skip both confirmed and rejected pairs on subsequent runs (alreadyTriedKeys union)
- Fix SAST FPR upload: use PROJECT_VERSION_ARTIFACTS restUpload (not UPLOAD_RESULT_FILE htmlUpload)
  to avoid duplicate scan GUID error in SSC
- Add AviatorSSCAttributeDefs + AviatorSSCAttributeHelper: create-if-not-exists last_correlation
  TEXT attribute definition on SSC instance, write ISO-8601 UTC timestamp after FPR uploads
- Add last_correlation attribute synchronization to prepare command (AviatorSSCPrepareHelper)
- Add Step 6c to correlate-sast-dast: write last_correlation timestamp after all FPR uploads
- Fix AviatorSSCCustomTagHelper: null-safe cast for valueList on TEXT-type tags (NullNode guard)
…sueList namespace lookup, add audit.xml validation

- Add receivedCorrelationResponses to CorrelationResult record for Phase 1 response count
- Output now includes succeeded (responses received) and skipped (submitted - succeeded)
- Fix SastFprCorrelationRecorder: fallback to no-namespace getElementsByTagName for IssueList
  in un-audited FPRs where audit.xml uses default (null) namespace
- Match parent IssueList namespace when creating new Issue elements
- Add audit.xml existence validation in parseSastFpr() and parseDastFpr()
- Prevent double-wrapping of FcliSimpleException in FPR parser catch blocks
…ttribute classes to correlation-specific names, remove admin-only auto-create from writeLastCorrelationTimestamp
feat: Add entitlement management to Aviator application
feat(ssc): Add bulkcorrelate action for automated SAST-DAST correlation of SSC application versions
…llback

fix: prefer FPR source file types over configured extension fallback
…trail

fix(aviator): record suppression state changes in audit history
chore: Add description key for applicationId parameter in add-entitlement command
Neeta Meshram and others added 28 commits June 15, 2026 11:42
Previously buildResultNode() used rd.asObjectNode() which dumped all
50+ FoDReleaseDescriptor fields into the output. Changed to create a
fresh ObjectNode with only releaseId, applicationName, releaseName,
and remediation metrics - matching the SSC helper pattern.
fix: FoD apply-remediation output shows only relevant fields
chore(aviator): align line-number enrichment with aviator-cli and initialize comment mapping
Integrate atomic remediations, FVDL encoding, and skip-reason reporting
from dev while keeping remediations-cache and issue-id filtering on this
branch.
Integrate atomic apply, FVDL encoding, and skip-reason reporting from
dev/v3.x with remediations-cache and issue-id filtering. Share metrics,
CLI validation, and SSC/FoD result JSON helpers.
…emediations-resolve

chore: resolve remediations conflicts after merging dev/v3.x
feat: `fcli aviator connection diagnose`: New command for generating Aviator server connectivity diagnostics

Co-authored-by: cdatla <cdatla@opentext.com>
chore: enforce HTTPS-only URL validation and stage logging
…ying (#1076)

* feat: add --preview flag to preview aviator remediations before applying

* fix: updated the output of --preview flag for apply-remediations command to display the correct value for __action__

* fix: Changed preview to a real type, reordered some of the output metrics for better readability, removed a redundant field and added tests for code that was not covered before.

* fix: align FoD --preview option with repository convention

* refactor: address code review feedback

- Introduce AbstractAviatorApplyRemediationsCommand base class shared by SSC and FoD
- Add ApplyRemediationsOptionsMixin and IApplyRemediationsOptions interface
- Simplify RemediationsApplyHelper.apply() signature; add @slf4j logger instead of passing LOG
- Add @builder to FileChange; replace IllegalArgumentException with AviatorBugException

* refactor: address PR review comments

  - Remove AviatorApplyRemediationsCliSupport class and moved its functionality to AbstractAviatorApplyRemediationsCommand
  - Replace separate methods for cache vs online with openFprSource/buildResultNode/isCacheMode to leverage IRemediationsFprSource
  - Split aggregateMetrics into aggregateUnfiltered/aggregateFiltered sub-methods
  - Use Lombok @builder in ChangeDetail to improve code readability

* fix: resolve build issue flagged by spotlessJavaCheck due to formatting violations

* refactor: address PR review comments
  - Rename source to fprSource for better clarity
  - Replace concrete mixin with abstract base + product-specific implementations
  - Move validation from commands to mixins
  - Remove IRecordTransformer interface
  - Remove stateful command fields
  - Enhance validation with StringUtils.isBlank() and path checks

* refactor: address PR review feedback
  - Rename SscApplyRemediationsOptionsMixin to AviatorSSCApplyRemediationsOptionsMixin
  - Rename FoDApplyRemediationsOptionsMixin to FoDAviatorApplyRemediationsOptionsMixin
  - Consolidate source selection into main options mixins
  - Replace manual getters with @Getter

---------

Co-authored-by: Dhanwanth Pratheep <dpratheep@opentext.com>
* Add DAST audit command and related functionality

- Implemented AviatorSSCDastAuditCommand for auditing DAST findings in SSC applications.
- Created DastAuditRequestMapper and DastAuditResponseMapper for handling DAST audit requests and responses.
- Added unit tests for DAST audit request and response mappers, stream processor, and command.
- Introduced AviatorSSCFprTransferHelper for managing DAST FPR downloads and uploads.
- Updated AviatorSSCAuditHelper to include DAST-specific audit statistics.
- Enhanced AviatorSSCCommands to include the new DAST audit command.
- Updated internationalization properties for DAST audit command messages.

* feat: Introduce SAST audit command and refactor DAST audit command

- Added `AviatorSSCSastAuditCommand` for auditing SAST findings in SSC applications.
- Updated `AviatorSSCDastAuditCommand` to return status names instead of enums.
- Refactored DAST audit result handling to use the new status name approach.
- Enhanced error handling for FPR uploads in `AviatorSSCFprTransferHelper`.
- Updated internationalization properties to include new SAST command and deprecate the old audit command.
- Added unit tests for the new SAST audit command and refactored existing tests for DAST audit command.
- Updated bulk audit YAML configuration to use the new SAST audit command.

* feat: Add refresh options to DAST audit command and corresponding tests

* feat: Refactor SSC audit commands and enhance DAST audit response summarization

* feat: Introduce AbstractAviatorSSCSastAuditCommand class for SAST audit functionality

---------

Co-authored-by: Ankit Rathod <arathod3@opentext.com>
…nd rename appliedRemediations key to availableRemediations only in --preview. (#1086)

Co-authored-by: Dhanwanth Pratheep <dpratheep@opentext.com>
* fix: exclude ineligible findings from DAST audits

Download the current SSC FPR state so suppression and audit metadata are honored before quota submission. Preserve server-provided DAST tiers through a typed domain model and harden stream result handling.

* fix: parse DAST tiers consistently

---------

Co-authored-by: Ankit Rathod <arathod3@opentext.com>
* feat: add bulk DAST audit action

* chore: refactor bulk Aviator auditing into dedicated SAST and DAST actions with backward compatibility

* chore: update bulkaudit action to log deprecation warning for bulkaudit-sast usage
…ersions (#1102)

* Align last_dast_audit selection with SAST-DAST correlation.

Compare the newest processed WebInspect scan date with the last_dast_audit timestamp, and accept ISO-8601 offsets without a colon in #date so that comparison works for SSC dates.

* chore: Improve bulk DAST audit controls and diagnostics

* Remove unnecessary shared SpEL date parsing changes
* Fix SSC SAST-DAST correlation state handling

* Report skipped correlation reasons

* Address SAST-DAST correlation review feedback

---------

Co-authored-by: Ankit Rathod <arathod3@opentext.com>
Co-authored-by: Umadevi Santhanam <usanthanam@opentext.com>
@kireetivar kireetivar self-assigned this Sep 30, 2026
* fix: `fcli aviator`: Stop warning for built-in SSC Aviator tags

* chore: `fcli aviator`: Tell SSC 26.2+ users to enable Aviator in SSC

* chore: fix internal tag detection

* chore: `fcli aviator`: Show each pre-upload tag warning once

* chore: `fcli aviator`: Load version custom tags through one request

* chore: `fcli aviator`: Use includeall as the only pre-upload tag list

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants