fix(orchestrator): refresh control_refs on existing findings during re-scan #228

Merged
sharang merged 1 commits from fix/refresh-control-refs into main 2026-07-22 12:24:37 +00:00
1 Commits
Author SHA1 Message Date
Sharang ParnerkarandClaude Opus 4.8 6af84c5216 fix(orchestrator): refresh control_refs on existing findings during re-scan
CI / Check (pull_request) Successful in 5m40s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (push) Skipped
The dedup loop only inserted first-seen findings; re-scans skipped existing
fingerprints entirely, so control_refs (re)computed by the mapping passes were
discarded. A finding first seen before control mapping was enabled/tuned would
therefore never gain its control mappings without being deleted + re-added.

Now: existing findings whose re-scan produced non-empty control_refs get updated
in place ($set control_refs). Guarded on non-empty so a run where mapping didn't
run (breakpilot unreachable) can't wipe existing refs. New findings unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 14:18:04 +02:00