Skip to content

fix[backend](tagrule): added tagrule tenant scoping - #2765

Merged
AlexSanchez-bit merged 1 commit into
release/v12.0.0from
backlog/v12_tagrule_scope_fix
Sep 28, 2026
Merged

AlexSanchez-bit merged 1 commit into
release/v12.0.0from
backlog/v12_tagrule_scope_fix

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

Copy link
Copy Markdown

🛑 AI review — High/critical findings

One or more high/critical issues were found. Please review and fix before merging if they're real.

✅ architecture (silas-1.7-pro) — clean

Summary: No architectural deviations detected; repository query was refactored from raw SQL to GORM without changing layering, contracts, or critical paths.

No findings.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: High: reusing the same GORM query builder after Count can carry COUNT(*)/statement state into Find, breaking list results.

  • high backend/modules/alerts/repository/alert_tag_pg.go:150 — q is reused for both Count and Find. GORM's Count mutates the shared statement (e.g. adds a COUNT(*) select), so the subsequent q.Find on line 155 may execute the wrong SQL or fail scanning into []domain.AlertTagRule. Reproduce by calling List and inspecting generated SQL or returned rows. Build separate query instances for count and list.

✅ security (silas-1.7-pro) — clean

Summary: No vulnerabilities introduced; the change replaces raw SQL with GORM query builder and does not add injection, disclosure, or auth issues.

No findings.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/aws:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/alerts:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/playground:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/azure:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./plugins/feeds:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260811073440-251cb9d842cd → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./plugins/soar:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./backend:
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit
AlexSanchez-bit merged commit 93559cc into release/v12.0.0 Sep 28, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_tagrule_scope_fix branch September 28, 2026 15:23
@AlexSanchez-bit AlexSanchez-bit linked an issue Sep 28, 2026 that may be closed by this pull request
2 of 3 tasks
@AlexSanchez-bit
AlexSanchez-bit restored the backlog/v12_tagrule_scope_fix branch September 28, 2026 16:31
Kbayero added a commit that referenced this pull request Sep 29, 2026
* Backlog/v12 mcp soar nodes discovery (#2754)

* fix[backend](mcp): add soar.node_types tool for flow node kind and executor discovery

* chore[](): updated go deps

* Backlog/v12 soar asisted edition (#2761)

* fix[frontend](soar-flows): removed redundant llm action node

* fix[backend](mcp/soar): updated flow properties schema in mcp catalog

* fix[frontend](soc-ai): drop dashboard chat scope when cleared outside dashboard view

* feat[frontend](soar/assitant): Edit with AI in flow editor

* feat[frontend](soar): click soar-edit panel header to open the active flow

* feat[frontend](soar): create flow with AI

* fix[backend](mcp/soar): fixed notifications type schema

* fix[backend](tagrule): added tagrule tenant scoping (#2765)

* fix[backend](execution): masked secret variables on execution history (#2767)

* fix[backend](execution): masked secret variables on execution history

* fix[backend](command): added start manual execution mask

* fix[backend](command): added soar flow execution variable masking

* fix[backend](visualizations): fixed tenat removal on visualization update (#2770)

* fix[frontend](soar): added variable interpolation in soar flows (#2771)

---------

Co-authored-by: Alex Sánchez <alex.sanchez@utmstack.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

leaked tagrules between tenants

1 participant