Skip to content

fix(report): HTML fix commands embed a cwd-relative path, so they are not runnable #1243

Description

@sonukapoor

Part of #733.

Fix commands in the HTML report embed a path computed relative to the current working directory, so a report generated from anywhere other than the project directory produces a command nobody can copy and run.

Generated from a temporary directory against a project elsewhere on disk, the override hygiene panel renders this:

cve-lite ../../../Users/sonukapoor/Projects/cve-lite-cli-v1.0.1/examples/all-scenarios overrides --fix --rule OA001

That is in a copy button, which is the whole point of the panel.

Why it matters

Running the scan from a different directory than the project is the normal case in CI, and the HTML report is the artefact people share with their team. A copy-and-run command is a core product principle here, and one containing ../../../Users/<somebody>/... is worse than no command, because it looks runnable.

Scope

The override hygiene panel is where this was found, but the same relative-path derivation is used for the fix command text, so check whether the CVE findings panel and the multi-folder report share it.

The likely answer is to emit a path relative to the scanned project, or the bare command with no path when the report is generated from within the project, rather than deriving from process.cwd() at render time.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinghelp wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions