Repository navigation
Conversation
create_server() built the ChromaDB collection — loading the all-MiniLM-L6-v2 sentence-transformers model as a side effect — before calling mcp.run(). The server therefore did not answer the MCP `initialize` handshake for ~43 s, well past the client's budget, and the connection failed with -32001. The failure was intermittent because seven MCP servers start concurrently, so whether it lost the race depended on CPU contention. It also presented as a broken server: probed by hand, the module imports and starts fine. Raising MCP_TIMEOUT only widened the window; the race remained. The collection is now built lazily behind a memoised accessor called from the tool bodies, so the handshake no longer waits on model loading. Measured: handshake 42.7 s -> 1.8 s. The one-time ~12 s model load moves to whichever of search_skills/get_skill/list_skills runs first. Carried in this commit from the same investigation: MCP_TIMEOUT in settings.json as a safety margin, and the mcp[cli] pin that made startup behaviour reproducible while diagnosing.
…d cwe Two changes to state-server, both touching update_vuln. 1. Pruning fired on the value passed, not on a transition -------------------------------------------------------- update_vuln called _prune_sibling_vulns() whenever status="actioned" was *passed*, not when the status actually *changed*. Since the prune query matches on in_graph = 1, every redundant re-assert hid whichever siblings happened to be visible at that moment, cascading a little further with each call. Observed in a live engagement: consolidation writes that re-asserted an already-actioned status hid 15 distinct, independently-scored findings from the dashboard graph, with no signal to the caller. The docstrings already described transition semantics — the code did not implement them. Both update_vuln and update_access now read the prior value first and fire prune/restore only on a genuine transition. Redundant writes are a graph no-op and omit siblings_pruned/siblings_restored from the response. 2. cvss_vector and cwe are now columns (schema v23) --------------------------------------------------- Both were previously recorded as free text inside `details`, so any downstream consumer had to recover them by regex — and every vulnerability-management tool treats them as first-class fields. Additive migration, idempotent, verified against a copy of a live 44-finding database. The vector is stored verbatim: not parsed, not validated, not scored.
Turns the vulns table into DefectDojo Findings, either as a Generic Findings Import file (--out, no network) or pushed to /api/v2/import-scan/ (--push). unique_id_from_tool is stable per vuln, so re-exporting updates existing findings instead of duplicating them. Standard library only. Three decisions worth stating: Info-severity findings are skipped by default. In red-run they are mostly refuted candidates and scope notes; importing them makes controls that held look like open issues. --include-info overrides. Provenance links are flattened into each finding's description under a "Provenance" heading. DefectDojo cannot represent the chain structurally, so the choice is prose or nothing. The tool prints what it did not export on every run. DefectDojo models vulnerabilities; red-run models an engagement. blocked, access, credentials and pivot_map have no counterpart and are dropped — and `blocked` in particular is what lets a reader tell "secure" apart from "not looked at". The omission is deliberate, so it is made visible rather than silent. The export carries the findings, not the narrative. It complements the engagement report; it does not replace it.
|
All contributors have signed the CLA ✍️ ✅ |
Author
|
I have read the CLA Document and I hereby sign the CLA |
bls-cla-bot Bot
added a commit
to blacklanternsecurity/CLA
that referenced
this pull request
Aug 11, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix skill-router startup handshake and graph pruning; add DefectDojo export