Complete scratch iteration 004 setup and grouped route-action fixes
This commit is contained in:
@@ -363,7 +363,8 @@ AdvisoryAI:
|
||||
|
||||
### Vulnerability Investigation
|
||||
|
||||
```n User: What is the status of CVE-2023-44487 in our environment?
|
||||
```text
|
||||
User: What is the status of CVE-2023-44487 in our environment?
|
||||
|
||||
Assistant: CVE-2023-44487 (HTTP/2 Rapid Reset) **is reachable** in your environment
|
||||
[reach:api-gateway:grpc.Server].
|
||||
@@ -376,12 +377,13 @@ Assistant: CVE-2023-44487 (HTTP/2 Rapid Reset) **is reachable** in your environm
|
||||
**Recommended actions:**
|
||||
[Accept Risk]{action:approve,cve_id=CVE-2023-44487}
|
||||
[Create VEX]{action:create_vex,product=api-gateway,vulnerability=CVE-2023-44487,status=affected}
|
||||
```n
|
||||
```
|
||||
---
|
||||
|
||||
### Action Execution
|
||||
|
||||
```n User: Please create a VEX statement marking CVE-2023-44487 as affected for api-gateway.
|
||||
```text
|
||||
User: Please create a VEX statement marking CVE-2023-44487 as affected for api-gateway.
|
||||
|
||||
Assistant: I will create a VEX statement with the following details:
|
||||
|
||||
@@ -391,7 +393,7 @@ Assistant: I will create a VEX statement with the following details:
|
||||
- **Justification:** Vulnerable code is reachable
|
||||
|
||||
[Create VEX Statement]{action:create_vex,product=api-gateway,vulnerability=CVE-2023-44487,status=affected,justification=vulnerable_code_present}
|
||||
```n
|
||||
```
|
||||
---
|
||||
|
||||
## Configuration
|
||||
|
||||
@@ -8,6 +8,10 @@
|
||||
|
||||
The Console presents operator dashboards for scans, policies, VEX evidence, runtime posture, and admin workflows.
|
||||
|
||||
## Latest updates (2026-03-12)
|
||||
- Console container builds now copy the repo `docs/` tree into the Angular build stage so `docs-content` is bundled into shipped images and direct `/docs/*` routes resolve on the live frontdoor instead of only in local dist copies.
|
||||
- Live search route verification now treats knowledge-card handoffs as failed unless the destination documentation page renders real content, preventing blank docs routes from slipping through route-only checks.
|
||||
|
||||
## Latest updates (2026-03-10)
|
||||
- Hardened revived `Ops > Policy > Simulation` direct-entry surfaces so coverage, lint, promotion-gate, and diff routes restore stable defaults when host wiring omits pack/version/environment inputs.
|
||||
- Coverage now hydrates on first render instead of waiting for a second interaction, preventing blank direct-route states on `/ops/policy/simulation/coverage`.
|
||||
|
||||
Reference in New Issue
Block a user