Compare commits

..
Author SHA1 Message Date
Sharang ParnerkarandClaude Opus 4.8 9c8f864a1d docs(control-mapping): MCP emission loop + flags now default-on
CI / Check (push) Skipped
CI / Check (pull_request) Successful in 5m47s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
- Add 'Emitting over MCP' section: the oscal_assessment tool, breakpilot's
  /v1/cra/oscal-from-scanner pull, and the tenant-context operational note
  (task_local lost across rmcp's session spawn -> bind tenant to the session).
- Configuration: semantic + grounded passes are now default-on (validated live),
  still no-op without BREAKPILOT_BASE_URL.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 13:14:59 +02:00
+1 -20
View File
@@ -277,10 +277,8 @@ impl PipelineOrchestrator {
}
}
// Dedup against existing findings: insert first-seen ones, and refresh the
// control mappings on ones we've seen before.
// Dedup against existing findings and insert new ones
let mut new_count = 0u32;
let mut refreshed_count = 0u32;
let mut new_findings: Vec<Finding> = Vec::new();
for mut finding in all_findings {
finding.scan_run_id = Some(scan_run_id.to_string());
@@ -295,25 +293,8 @@ impl PipelineOrchestrator {
finding.id = result.inserted_id.as_object_id();
new_findings.push(finding);
new_count += 1;
} else if !finding.control_refs.is_empty() {
// Re-scan refresh: a mapping pass (newly enabled or tuned) computed
// control_refs for a finding first seen before mapping ran. Persist
// them onto the existing row — the insert path alone never would.
self.db
.findings()
.update_one(
doc! { "fingerprint": &finding.fingerprint },
doc! { "$set": { "control_refs": finding.control_refs.clone() } },
)
.await?;
refreshed_count += 1;
}
}
if refreshed_count > 0 {
tracing::info!(
"[{repo_id}] Refreshed control_refs on {refreshed_count} existing findings"
);
}
// Remove stale SBOM entries for this repo before reinserting
if !sbom_entries.is_empty() {