Allow STO to display and track rescans for prior pipeline executions (immutable history + latest results)
R
Rubber Scallop
We are required to rescan previously completed builds every ~4-hours to detect newly disclosed vulnerabilities and severity re-ratings. These rescans will be initiated on the backend (not by re-running the original pipeline execution).
Today, Harness STO does not support updating the STO dashboard view for a specific historical build after a rescan. As a result, a vulnerability that is newly detected (or an existing vulnerability whose severity increases) is not reflected for the original pipeline execution/build in the STO dashboard.
Requested Enhancement
Provide a first-class “rescan” capability for historical builds such that:
- Rescan results can be associated to an existing build identified by pipeline execution ID and/or build number.
- STO preserves the original scan results (immutable snapshot) including the original scan date/time.
- When a backend rescan occurs, STO creates a new dated rescan entry/view for that same build and highlights what changed (e.g., new vulnerabilities, severity changes, updated counts).
- The STO dashboard for that build can show:
--- Original scan (timestamped)
--- Latest rescan (timestamped)
--- Delta/change view between scans
Why this matters
This enables continuous vulnerability management for already-built artifacts and ensures the STO dashboard reflects the current security posture of prior builds as vulnerability intelligence evolves.