MCPcopy Create free account
hub / github.com/Kilo-Org/cloud / syncAutoAnalysisQueueForFinding

Function syncAutoAnalysisQueueForFinding

services/security-sync/src/sync.ts:1149–1285  ·  view source on GitHub ↗
(
  db: WorkerDb,
  params: {
    owner: SecurityReviewOwner;
    findingId: string;
    findingCreatedAt: string;
    previousStatus: SecurityFindingStatus | null;
    currentStatus: SecurityFindingStatus;
    severity: string | null;
    isAgentEnabled: boolean;
    autoAnalysisEnabled: boolean;
    autoAnalysisMinSeverity: AutoAnalysisMinSeverity;
    ownerAutoAnalysisEnabledAt: string | null;
    autoAnalysisIncludeExisting?: boolean;
  }
)

Source from the content-addressed store, hash-verified

1147 params: {
1148 finding: ParsedSecurityFinding;
1149 owner: SecurityReviewOwner;
1150 platformIntegrationId: string;
1151 repoFullName: string;
1152 slaDueAt: string;
1153 }
1154): Promise<UpsertSecurityFindingResult> {
1155 const { finding, owner, platformIntegrationId, repoFullName, slaDueAt } = params;
1156 const ownerOrganizationId = isOrgOwner(owner) ? owner.organizationId : null;
1157 const ownerUserId = isOrgOwner(owner) ? null : owner.userId;
1158
1159 // Only rewrite an existing finding when the source data actually changed. Re-syncing an
1160 // unchanged finding otherwise rewrote the row on every run (bumping last_synced_at/
1161 // updated_at), which — multiplied by ~13 indexes and the TOASTed raw_data column —
1162 // produced large amounts of WAL for findings that had not changed.
1163 //
1164 // Every stored column is derived from the Dependabot alert (see parseDependabotAlert),
1165 // and GitHub only advances the alert's updated_at on real changes, so comparing the
1166 // stored raw_data (jsonb, order-independent) detects any source-driven change in one
1167 // check. sla_due_at is the only value we compute ourselves, so it is compared separately
1168 // to catch SLA-policy changes. When neither differs the DO UPDATE matches no row and the
1169 // fallback SELECT below returns the existing finding with wasInserted=false and no
1170 // status/severity delta, so notifications and audit events behave exactly as they did for
1171 // an unchanged re-sync.
1172 const materialChangePredicate = sql`(
1173 ${security_findings.raw_data} IS DISTINCT FROM EXCLUDED.${sql.identifier(security_findings.raw_data.name)}
1174 OR ${security_findings.sla_due_at} IS DISTINCT FROM EXCLUDED.${sql.identifier(security_findings.sla_due_at.name)}
1175 )`;
1176
1177 const result = await db.execute<Record<string, unknown>>(sql`
1178 WITH existing_match AS (
1179 SELECT ${security_findings.id} AS id,
1180 ${security_findings.status} AS previous_status,
1181 ${security_findings.severity} AS previous_severity
1182 FROM ${security_findings}
1183 WHERE ${security_findings.repo_full_name} = ${repoFullName}
1184 AND ${security_findings.source} = ${finding.source}
1185 AND ${security_findings.source_id} = ${finding.source_id}
1186 AND ${findingOwnerPredicate(owner)}
1187 FOR UPDATE
1188 ),
1189 upserted AS (
1190 INSERT INTO ${security_findings} (
1191 ${sql.identifier(security_findings.owned_by_organization_id.name)},
1192 ${sql.identifier(security_findings.owned_by_user_id.name)},
1193 ${sql.identifier(security_findings.platform_integration_id.name)},
1194 ${sql.identifier(security_findings.repo_full_name.name)},
1195 ${sql.identifier(security_findings.source.name)},
1196 ${sql.identifier(security_findings.source_id.name)},
1197 ${sql.identifier(security_findings.severity.name)},
1198 ${sql.identifier(security_findings.ghsa_id.name)},
1199 ${sql.identifier(security_findings.cve_id.name)},
1200 ${sql.identifier(security_findings.package_name.name)},
1201 ${sql.identifier(security_findings.package_ecosystem.name)},
1202 ${sql.identifier(security_findings.vulnerable_version_range.name)},
1203 ${sql.identifier(security_findings.patched_version.name)},
1204 ${sql.identifier(security_findings.manifest_path.name)},
1205 ${sql.identifier(security_findings.title.name)},
1206 ${sql.identifier(security_findings.description.name)},

Callers 2

sync.test.tsFile · 0.85
syncRepoFunction · 0.85

Calls 7

isOrgOwnerFunction · 0.85
transactionMethod · 0.65
setMethod · 0.65
updateMethod · 0.65
valuesMethod · 0.65
sqlFunction · 0.50

Tested by

no test coverage detected