(
db: WorkerDb,
params: {
owner: SecurityReviewOwner;
findingId: string;
findingCreatedAt: string;
previousStatus: SecurityFindingStatus | null;
currentStatus: SecurityFindingStatus;
severity: string | null;
isAgentEnabled: boolean;
autoAnalysisEnabled: boolean;
autoAnalysisMinSeverity: AutoAnalysisMinSeverity;
ownerAutoAnalysisEnabledAt: string | null;
autoAnalysisIncludeExisting?: boolean;
}
)
| 1147 | params: { |
| 1148 | finding: ParsedSecurityFinding; |
| 1149 | owner: SecurityReviewOwner; |
| 1150 | platformIntegrationId: string; |
| 1151 | repoFullName: string; |
| 1152 | slaDueAt: string; |
| 1153 | } |
| 1154 | ): Promise<UpsertSecurityFindingResult> { |
| 1155 | const { finding, owner, platformIntegrationId, repoFullName, slaDueAt } = params; |
| 1156 | const ownerOrganizationId = isOrgOwner(owner) ? owner.organizationId : null; |
| 1157 | const ownerUserId = isOrgOwner(owner) ? null : owner.userId; |
| 1158 | |
| 1159 | // Only rewrite an existing finding when the source data actually changed. Re-syncing an |
| 1160 | // unchanged finding otherwise rewrote the row on every run (bumping last_synced_at/ |
| 1161 | // updated_at), which — multiplied by ~13 indexes and the TOASTed raw_data column — |
| 1162 | // produced large amounts of WAL for findings that had not changed. |
| 1163 | // |
| 1164 | // Every stored column is derived from the Dependabot alert (see parseDependabotAlert), |
| 1165 | // and GitHub only advances the alert's updated_at on real changes, so comparing the |
| 1166 | // stored raw_data (jsonb, order-independent) detects any source-driven change in one |
| 1167 | // check. sla_due_at is the only value we compute ourselves, so it is compared separately |
| 1168 | // to catch SLA-policy changes. When neither differs the DO UPDATE matches no row and the |
| 1169 | // fallback SELECT below returns the existing finding with wasInserted=false and no |
| 1170 | // status/severity delta, so notifications and audit events behave exactly as they did for |
| 1171 | // an unchanged re-sync. |
| 1172 | const materialChangePredicate = sql`( |
| 1173 | ${security_findings.raw_data} IS DISTINCT FROM EXCLUDED.${sql.identifier(security_findings.raw_data.name)} |
| 1174 | OR ${security_findings.sla_due_at} IS DISTINCT FROM EXCLUDED.${sql.identifier(security_findings.sla_due_at.name)} |
| 1175 | )`; |
| 1176 | |
| 1177 | const result = await db.execute<Record<string, unknown>>(sql` |
| 1178 | WITH existing_match AS ( |
| 1179 | SELECT ${security_findings.id} AS id, |
| 1180 | ${security_findings.status} AS previous_status, |
| 1181 | ${security_findings.severity} AS previous_severity |
| 1182 | FROM ${security_findings} |
| 1183 | WHERE ${security_findings.repo_full_name} = ${repoFullName} |
| 1184 | AND ${security_findings.source} = ${finding.source} |
| 1185 | AND ${security_findings.source_id} = ${finding.source_id} |
| 1186 | AND ${findingOwnerPredicate(owner)} |
| 1187 | FOR UPDATE |
| 1188 | ), |
| 1189 | upserted AS ( |
| 1190 | INSERT INTO ${security_findings} ( |
| 1191 | ${sql.identifier(security_findings.owned_by_organization_id.name)}, |
| 1192 | ${sql.identifier(security_findings.owned_by_user_id.name)}, |
| 1193 | ${sql.identifier(security_findings.platform_integration_id.name)}, |
| 1194 | ${sql.identifier(security_findings.repo_full_name.name)}, |
| 1195 | ${sql.identifier(security_findings.source.name)}, |
| 1196 | ${sql.identifier(security_findings.source_id.name)}, |
| 1197 | ${sql.identifier(security_findings.severity.name)}, |
| 1198 | ${sql.identifier(security_findings.ghsa_id.name)}, |
| 1199 | ${sql.identifier(security_findings.cve_id.name)}, |
| 1200 | ${sql.identifier(security_findings.package_name.name)}, |
| 1201 | ${sql.identifier(security_findings.package_ecosystem.name)}, |
| 1202 | ${sql.identifier(security_findings.vulnerable_version_range.name)}, |
| 1203 | ${sql.identifier(security_findings.patched_version.name)}, |
| 1204 | ${sql.identifier(security_findings.manifest_path.name)}, |
| 1205 | ${sql.identifier(security_findings.title.name)}, |
| 1206 | ${sql.identifier(security_findings.description.name)}, |
no test coverage detected