Part of #733.
Fix commands in the HTML report embed a path computed relative to the current working directory, so a report generated from anywhere other than the project directory produces a command nobody can copy and run.
Generated from a temporary directory against a project elsewhere on disk, the override hygiene panel renders this:
cve-lite ../../../Users/sonukapoor/Projects/cve-lite-cli-v1.0.1/examples/all-scenarios overrides --fix --rule OA001
That is in a copy button, which is the whole point of the panel.
Why it matters
Running the scan from a different directory than the project is the normal case in CI, and the HTML report is the artefact people share with their team. A copy-and-run command is a core product principle here, and one containing ../../../Users/<somebody>/... is worse than no command, because it looks runnable.
Scope
The override hygiene panel is where this was found, but the same relative-path derivation is used for the fix command text, so check whether the CVE findings panel and the multi-folder report share it.
The likely answer is to emit a path relative to the scanned project, or the bare command with no path when the report is generated from within the project, rather than deriving from process.cwd() at render time.
Part of #733.
Fix commands in the HTML report embed a path computed relative to the current working directory, so a report generated from anywhere other than the project directory produces a command nobody can copy and run.
Generated from a temporary directory against a project elsewhere on disk, the override hygiene panel renders this:
That is in a copy button, which is the whole point of the panel.
Why it matters
Running the scan from a different directory than the project is the normal case in CI, and the HTML report is the artefact people share with their team. A copy-and-run command is a core product principle here, and one containing
../../../Users/<somebody>/...is worse than no command, because it looks runnable.Scope
The override hygiene panel is where this was found, but the same relative-path derivation is used for the fix command text, so check whether the CVE findings panel and the multi-folder report share it.
The likely answer is to emit a path relative to the scanned project, or the bare command with no path when the report is generated from within the project, rather than deriving from
process.cwd()at render time.