Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | SCA-109 add version to IssueReleaseDetails and pass purl_in_use to ↵ | Havoc Pennington | 2 days | 1 | -31/+37 |
| | | | | vulnerability details cloud API | ||||
* | SCA-106 Return "createdAt" along with dependency risks. | Tieg Zaharia | 3 days | 1 | -3/+6 |
| | | | Co-authored-by: Havoc Pennington <havoc.pennington@sonarsource.com> | ||||
* | SQRP-252 Purge SCA tables when a branch is deleted | Madeline Cowie | 3 days | 1 | -0/+38 |
| | |||||
* | SQRP-268 Adds endpoint to fetch a dependency risk, including vuln details. | Tieg Zaharia | 4 days | 1 | -4/+34 |
| | | | Co-authored-by: Havoc Pennington <hp@pobox.com> | ||||
* | SONAR-24588 Search for releases with before and after instead of just the ↵ | Jeremy Katz | 6 days | 1 | -4/+4 |
| | | | | beginning of the string | ||||
* | SQRP-308 add the newInPullRequest filter to releases and risks endpoints | Havoc Pennington | 6 days | 2 | -25/+49 |
| | | | | Also, default it to true on pull requests. | ||||
* | SQRP-308 add a new_in_pull_request column to sca_releases and sca_dependencies | Havoc Pennington | 6 days | 2 | -0/+4 |
| | |||||
* | SQRP-275 Add counts of releases by package manager in releases endpoint | Jeremy Katz | 8 days | 1 | -0/+19 |
| | | | This will enable the frontend to know what package managers are in use by a project to show the correct things in the left filter bar | ||||
* | SQRP-299 Add query with filter/sort to ScaIssuesReleasesDetailsDao | Havoc Pennington | 10 days | 1 | -1/+433 |
| | |||||
* | SQRP-249 add ScaIssueReleaseDetailsDto and mapper | Havoc Pennington | 10 days | 1 | -0/+90 |
| | | | | | | | | | | | | | | | | This is used to query SCA issues for a single analysis with all the necessary tables joined to it to get the full issue context. SQRP-301 rename DbTester.getIssuesWithScaDbTester to getScaIssuesReleasesDetailsDbTester SQRP-301 rename DbClient.issuesWithScaDao to scaIssuesReleasesDao SQRP-301 add better doc comment to ScaIssueReleaseDetailsDto on meaning of identity fields in sca_issues_releases dbtester, fix to work after separating new/insert SQRP-296 port ScaIssueReleaseDetails to query cve_ids not title | ||||
* | SQRP-292 Add sca_issues_releases | Travis Collins | 10 days | 1 | -0/+109 |
| | | | | | | | | SQRP-293 add sca_issues_releases.severity column SQRP-292 Update sca_issues_releases Dao to support persisting SQRP-300 Add sca_issues_releases.severity_sort_key | ||||
* | SQRP-246 Register a UUID for SCA issues in sca_issues table | Havoc Pennington | 10 days | 2 | -0/+275 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This gives each issue a UUID that spans projects & analyses. SQRP-246 remove "get" from DbClient getter for sca issues DAO This wasn't following the naming convention. SQRP-287 add "IfApplicable" methods to ScaIssue These handle two things: * blank values become Optional.empty instead of junk * allows us to get all applicable values from a ScaIssue reference without type-casting. SQRP-287 add ScaIssuesDbTester Utility methods for ScaIssues testing SQRP-287 use a magic string value instead of empty string in ScaIssueDto Because Oracle considers empty string to be a synonym for null. SQRP-287 ScaIssuesDbTester vary the license saved in test issues SQRP-247 add more unit tests for ScaIssueDto SQRP-287 rename ScaIssue.titleIfApplicable => vulnerabilityTitleIfApplicable SQRP-246 make assertColumnDefinition work with DECIMAL on H2 SQRP-293 add base_severity to sca_vulnerability_issues This is the severity prior to any project-specific factors such as reachability. SQRP-293 increase ScaIssue test coverage SQRP-246 Add ScaIssueDto.Builder SQRP-246 Use a short placeholder CVE title, not giant description SQRP-246 Add toString to ScaIssue subtypes in sca_issues dbtester, separate new from insert SQRP-296 replace sca_vulnerability_issues.title with cwe_ids Replace title with cweIds in ScaIssue Remove ScaIssueFactory to be put back with IssuesReleases Replace title with cweids in the steps Change severity to INFO, LOW, MEDIUM, HIGH | ||||
* | SCA-56 Run "reformat code" on SCA files | Havoc Pennington | 2025-02-28 | 1 | -1/+0 |
| | |||||
* | SQRP-191 Ingest and persist the new "chains" field on each dependency | Tieg Zaharia | 2025-02-28 | 1 | -2/+2 |
| | | | Co-authored-by: Travis Collins <travistx@gmail.com> | ||||
* | SQRP-156 A frontend-used API is created that returns a CycloneDX SBOM for a ↵ | John Bintz | 2025-02-28 | 1 | -8/+4 |
| | | | | | project Co-authored-by: Antoine Vinot <antoine.vinot@sonarsource.com> | ||||
* | SQRP-242 Add releases endpoints | Travis Collins | 2025-02-28 | 2 | -0/+32 |
| | |||||
* | SQRP-191 add new "sca_dependencies.chains" column | Tieg Zaharia | 2025-02-19 | 1 | -0/+2 |
| | |||||
* | SQRP-221 Add sca_releases table splitting out part of sca_dependencies | Havoc Pennington | 2025-02-19 | 2 | -46/+292 |
| | | | | | | | | This will allow us to do paginated queries of releases instead of dependencies. In this commit, the behavior of the dependencies endpoint is not changed; this commit sets it up to be change-able, but just keeps it the same for the time being. | ||||
* | SQRP-188 Add filtering to "search" dependencies REST API | Javier García Orduña | 2025-02-19 | 1 | -50/+82 |
| | |||||
* | SQRP-140 Expose dependency details with new REST APIs | Javier García Orduña | 2025-02-19 | 1 | -183/+0 |
| | |||||
* | SQRP-172 fix typo in selectByUuid in ScaDependenciesMapper | Havoc Pennington | 2025-02-19 | 1 | -0/+9 |
| | |||||
* | SQRP-138 Create the sca_dependencies database table | Havoc Pennington | 2025-02-19 | 1 | -0/+198 |
| | |||||
* | SQRP-154 Cleanup leftovers from FOSSA | Javier García Orduña | 2025-02-04 | 4 | -267/+0 |
| | |||||
* | SONAR-24216 Optimize querying of measures on startup indexing | Eric Giffon | 2025-01-28 | 1 | -1/+1 |
| | |||||
* | SONAR-23122 Add telemetry to async issue index creation at startup. | Steve Marion | 2025-01-10 | 1 | -0/+54 |
| | |||||
* | SONAR-19225 Drop BCRYPT hash method for user passwords | Matteo Mara | 2025-01-09 | 2 | -3/+3 |
| | |||||
* | SONAR-23711 Retrieve rules based on mode | OrlovAlexander | 2025-01-09 | 2 | -0/+58 |
| | |||||
* | SONAR-24146 Update license headers for 2025 | Matteo Mara | 2025-01-09 | 118 | -118/+118 |
| | |||||
* | SONAR-14367 Add new field to ProjectAlmSettingDto and update queries | Jacek Poreda | 2025-01-09 | 1 | -5/+31 |
| | |||||
* | SONAR-24122 Fix application refresh not refreshing referencers | Duarte Meneses | 2025-01-06 | 1 | -13/+1 |
| | | | Co-authored-by: Cody Simms <cody.simms@sonarsource.com> | ||||
* | SONAR-23119 Create 'migration_logs' table | Alain Kermis | 2025-01-03 | 1 | -0/+79 |
| | |||||
* | SONAR-23978 Detect AI Code | Dejan Milisavljevic | 2024-12-20 | 1 | -0/+22 |
| | |||||
* | SONAR-23984 Add Scheduler to fetch information about Copilot usage | Léo Geoffroy | 2024-12-20 | 1 | -0/+66 |
| | |||||
* | SONAR-23978 Add DAO for user_ai_tool_usages table | Léo Geoffroy | 2024-12-20 | 1 | -0/+82 |
| | |||||
* | SONAR-24057 Optimize querying of branch measures to only load required ↵ | Eric Giffon | 2024-12-20 | 2 | -173/+40 |
| | | | | measures in memory | ||||
* | SONAR-24004 Replace lambda with method reference | Julien Camus | 2024-12-18 | 2 | -19/+14 |
| | |||||
* | SONAR-22998 fetch active rules with a dedicated endpoint | Pierre Guillot | 2024-12-18 | 1 | -8/+66 |
| | | | Co-authored-by: Julien HENRY <julien.henry@sonarsource.com> | ||||
* | SONAR-23734 Total number of applications Telemetry | OrlovAlexander | 2024-12-18 | 1 | -0/+10 |
| | |||||
* | SONAR-23738 Portfolio and Subportfolio selection mode telemetry | OrlovAlexander | 2024-12-18 | 1 | -0/+28 |
| | |||||
* | SONAR-23688 Index active rules impacts | Dejan Milisavljevic | 2024-12-06 | 1 | -16/+26 |
| | |||||
* | SONAR-23731 Portfolio report telemetry | OrlovAlexander | 2024-12-06 | 1 | -2/+10 |
| | |||||
* | SONAR-23512 Project report telemetry | OrlovAlexander | 2024-12-06 | 1 | -0/+24 |
| | |||||
* | SONAR-23736 Add application report Telemetry | OrlovAlexander | 2024-12-04 | 1 | -0/+26 |
| | |||||
* | SONAR-23619 Add Sonar way for AI Code Quality Gate | Jacek | 2024-11-29 | 2 | -6/+22 |
| | |||||
* | SONAR-23619 Rename ai_code_assurance_column (#12320) | Anita Stanisz | 2024-11-29 | 1 | -12/+12 |
| | |||||
* | SONAR-23619 Add 'isAiCodeSupported' flag to show and list endpoints of ↵ | Jacek Poreda | 2024-11-29 | 1 | -0/+9 |
| | | | | Quality Gates | ||||
* | SONAR-23619 Add DB migration for 'quality_gates' table to add ↵ | Jacek Poreda | 2024-11-29 | 1 | -0/+1 |
| | | | | 'ai_code_supported' boolean flag | ||||
* | SONAR-23637 Export of CSV finding files includes impacts | OrlovAlexander | 2024-11-27 | 1 | -1/+6 |
| | |||||
* | SONAR-23649 Conditions mismatch notification should be enabled by default ↵ | Léo Geoffroy | 2024-11-26 | 1 | -56/+75 |
| | | | | for Quality gate administrators | ||||
* | CODEFIX-192 Add ai code fix enablement to audit logs (#12238) | Serhat Yenican | 2024-11-19 | 1 | -4/+8 |
| |