feat(cli): browse historical security findings - #275
Conversation
…gs-history-discovery
…gs-history-discovery
|
@codex review |
There was a problem hiding this comment.
Pull request overview
This PR adds first-class CLI support for browsing historical scan findings, including repository-scoped and scan-scoped finding lists, a dedicated finding-details view, and improved scan-history rendering that makes follow-up actions (pagination, details, matching, comparison) more discoverable.
Changes:
- Introduces
codex-security findings list/findings showflows (plusfindingsdefaulting tolist) and enhancesscans showto support a “latest completed scan” default. - Extends the TypeScript renderer to format saved-findings pages and full finding details (locations, evidence, remediation guidance, history links, pagination hints).
- Expands the bundled Python workbench to support
get-finding, richer scan-history scoping for moved/nested checkouts, and global findings indexing improvements (including secondary-location search).
Reviewed changes
Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| sdk/typescript/tests-ts/workbench-findings-index.test.ts | Adds regression coverage for global findings indexing (scoping, filtering, coverage-read behavior, tamper/noncanonical handling, detail vs preview completeness). |
| sdk/typescript/tests-ts/scan-history-renderer.test.ts | Adds renderer coverage for actionable findings/history output, pagination hints, triage precedence, and next-command suggestions. |
| sdk/typescript/tests-ts/runtime.test.ts | Adds coverage ensuring large get-finding responses are allowed while oversize non-detail workbench responses fail safely without leaking content. |
| sdk/typescript/tests-ts/cli.test.ts | Updates CLI manifest assertions for new findings commands and revised scans show signature. |
| sdk/typescript/tests-ts/cli-findings.test.ts | Adds CLI tests for repository scoping, paging/filter validation, scan selection, and “latest scan” behavior. |
| sdk/typescript/src/scan-history-renderer.ts | Implements new findings/finding render modes, checkout scoping helpers, and improved list/show guidance (pagination, matching, compare suggestions). |
| sdk/typescript/src/runtime.ts | Adds separate workbench stdout limits for list-style commands vs get-finding, with safer maxBuffer error redaction. |
| sdk/typescript/src/cli.ts | Adds findings list/show commands, defaults findings/scans to list, and supports scans show without an explicit scan ID (latest completed). |
| sdk/typescript/README.md | Documents the new scan-history and findings browsing commands and how to page/filter results. |
| sdk/typescript/_bundled_plugin/scripts/workbench_scan_history.py | Improves repository scoping to handle moved checkouts, nested boundaries, and reused paths more safely; includes currentTargetPath projection. |
| sdk/typescript/_bundled_plugin/scripts/workbench_native_indexes.py | Adds multi-target support, legacy-path support, and secondary-location searching for global findings queries. |
| sdk/typescript/_bundled_plugin/scripts/workbench_db.py | Adds get-finding, supports full-details finding serialization, and strips forged metadata fields from stored details while preserving authoritative triage. |
| sdk/typescript/_bundled_plugin/scripts/workbench_cli.py | Extends the workbench CLI surface with get-finding and multi-valued --target-id/--target-path for global findings. |
| README.md | Updates top-level docs to mention scans show latest behavior and the new findings browsing commands. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 223ecf3e75
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f0dc21af02
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
kmbroai
left a comment
There was a problem hiding this comment.
Reviewed head dc1e121a3d111b5adb9991562a52350c9e9b252e for correctness, necessity, and simplification.
[P2] Ship the changed workbench under a fresh plugin version
Both this head and its base declare bundled plugin 0.1.20. I ran this head's actual bootstrapPlugin with the local native Codex installer: install the base bundle into a new isolated home, then bootstrap this bundle into the same home. The installed workbench_db.py still had the base hash, not this PR's hash. In particular, the new aggregate-status check in require_finding_open was present in the source bundle but absent from the installed workbench.
This matters beyond browser appearance: the SDK's direct workbench calls can use the new bundled code while the installed MCP workbench retains the old per-occurrence remediation guard. A finding dismissed through a matched occurrence can consequently be presented as closed by the new projection without the installed helper receiving the corresponding guard fix. Bump both version declarations, or explicitly land only as part of a coordinated fresh-version release. Test an upgrade from an already installed bundle, not just a clean install. No model call was needed for this cache reproduction.
Current correctness and prior feedback
I checked the full comment history against the current source rather than repeating old findings. The repository-plus---scan conflict is now rejected; aggregate triage reaches remediation checks; targetless scan details use the shared index; grouped counts distinguish occurrences from distinct scans; and the pagination documentation explains repeated nextOffset traversal. A direct SQLite/Git fixture also confirmed that the latest legacy-child/registered-ancestor complaint is fixed: both the modern ancestor scan and legacy child scan are selected.
Necessity and simplification
Finding IDs, full detail, filtering, and explicit pagination are useful additions. This PR also rewrites repository ownership discovery, active/resolved projection, semantic grouping, triage propagation, and scan ordering. Those are correctness changes, not merely a browser, and should be separated from terminal presentation where practical.
Use #456's generation/scope model as the shared foundation instead of maintaining a second ownership-epoch implementation here. Preserve one aggregate-status computation for lists, details, and action guards. The TTY-only auto-pagination loop is optional convenience; a consistently paged interface would remove a special execution path and repeated index reconstruction without losing access to any finding.
Verification
Four focused index, repository-findings, CLI, and renderer suites: 71 passed, 0 failed, with cached dependencies. Also ran the ancestor-scope and real local plugin-upgrade probes. No production history, live remediation, or native Windows execution was exercised.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsAdvisory findings (7)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cf65c935b9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3b9f7772f2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ea7b063899
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Non-CI blockers on exact head
The branch is also currently merge-conflicting. When updating it to current I independently reproduced the ownership-scope selection, explicit-reopen no-op, and unavailable-checkout comparison failures. The five corresponding review threads remain unresolved on this head. |
|
@codex review Current head: |
|
@codex security review Current head: |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 85a5ce80c7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Current head: |
|
@codex security review Current head: |
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review Please review the current head, |
|
@codex security review Please review the current head, |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
Browse saved findings by repository or scan, with consistent occurrence history and triage across lists, details, comparisons, CSV exports, and remediation. Preserve saved details when a checkout is offline while keeping replaced checkout owners isolated.
Changes
findings list [REPOSITORY]with--scan,--all-repositories, query/severity/status filters, and pagination. Repository views default to open findings; scan views include all findings. Pages default to 20 and honor larger--limit Nvalues. Home-relative repository paths use the existing CLI path resolver.findings show OCCURRENCE_IDandscans show latest. Preserve JSON pagination and automatic paging for the unfiltered interactive repository view.Testing
12345and809688597: 2,178 passed, 43 skipped, and no failures in each run.Risk and rollout
This extends the public history CLI with the syntax above and removes the fixed collection-page cap; the default remains 20. The UX cleanup preserves accepted values, defaults, and JSON response fields. There is no database migration or npm package-version change. Completed artifacts, credentials, sealed-artifact checks, and ownership boundaries remain protected. Cached plugin upgrades from 0.1.79, 0.1.85, 0.1.86, and 0.1.87 are covered. Cross-platform CI and Codex reviews run on the pushed head.
Public disclosure review
Existing automated review comments contain access-restricted report references, so the second attestation remains unchecked.