Skip to content

Surface and filter ai classification on results show(AST-178033) - #1579

Closed
cx-sumit-morchhale wants to merge 4 commits into
mainfrom
feature/AST-178033-surface-filter-aiclassification-results
Closed

cx-sumit-morchhale wants to merge 4 commits into
mainfrom
feature/AST-178033-surface-filter-aiclassification-results

Conversation

@cx-sumit-morchhale

Copy link
Copy Markdown
Contributor

Summary

  • Surfaces the aiClassification field (TP/FP/UNCLASSIFIED/NOT_ANALYZED) that ast-results now returns on GET /api/results for SAST results (AST-175453) into both the CLI's JSON and SARIF reports — previously silently dropped since ScanResultData had no matching field.
  • Documents the existing --filter "ai-classification=TP;FP" pass-through in results show's help text (filtering already worked by accident via the generic --filter mechanism; this just makes it discoverable).
  • Absent/omitted when the API omits the key (non-SAST result, or the phase-2 flag off for the tenant) — no client-side feature-flag gate needed, the CLI just reflects whatever ast-results sends.

Changes

  • internal/wrappers/results-json.go — add AIClassification *string (omitempty) to ScanResultData.
  • internal/wrappers/results-sarif.go — add AIClassification *string (omitempty) to SarifResultProperties.
  • internal/commands/result.go — populate SarifResultProperties.AIClassification in parseSarifResultSast when present; list ai-classification in filterResultsListFlagUsage.
  • internal/params/flags.go — add AIClassificationQueryParam constant.
  • internal/wrappers/mock/results-mock.go — seed one mock SAST result with a classification for test coverage.
  • internal/commands/result_test.go — cover present/absent cases for both JSON and SARIF output.

Out of scope

  • sonar and gl-sast reports (externally-owned schemas, no field for this) and pdf (server-rendered) — unchanged.

@stepsecurity-app

Copy link
Copy Markdown
Contributor

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.CX_BASE_URI at line 221
  • secrets.CX_CLIENT_ID at line 222
  • secrets.CX_CLIENT_SECRET at line 223
  • secrets.CX_BASE_AUTH_URI at line 224
  • secrets.CX_AST_USERNAME at line 225
  • secrets.CX_AST_PASSWORD at line 226
  • secrets.CX_APIKEY at line 227
  • secrets.CX_TENANT at line 228
  • secrets.CX_SCAN_SSH_KEY at line 229
  • secrets.ECHO_LIBRARIES_ACCESS_KEY at line 231
  • secrets.PERSONAL_ACCESS_TOKEN at line 233
  • secrets.PROXY_USER at line 236
  • secrets.PROXY_PASSWORD at line 237
  • secrets.PR_GITLAB_TOKEN at line 242
  • secrets.PR_GITLAB_NAMESPACE at line 243
  • secrets.PR_GITLAB_REPO_NAME at line 244
  • secrets.PR_GITLAB_PROJECT_ID at line 245
  • secrets.PR_GITLAB_IID at line 246
  • secrets.AZURE_ORG at line 247
  • secrets.AZURE_PROJECT at line 248
  • secrets.AZURE_REPOS at line 249
  • secrets.AZURE_TOKEN at line 250
  • secrets.BITBUCKET_WORKSPACE at line 252
  • secrets.BITBUCKET_REPOS at line 253
  • secrets.BITBUCKET_USERNAME at line 254
  • secrets.BITBUCKET_PASSWORD at line 255
  • secrets.GITLAB_TOKEN at line 256
  • secrets.PR_BITBUCKET_TOKEN at line 258
  • secrets.MS_TEAMS_WEBHOOK_URL_INTEGRATION_TESTS at line 437

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-sumit-morchhale) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant