Skip to content

integration branch for multiple pr (AST-136045)#258

Merged
cx-nisan-benabu merged 19 commits into
mainfrom
release/integration
Jun 25, 2026
Merged

integration branch for multiple pr (AST-136045)#258
cx-nisan-benabu merged 19 commits into
mainfrom
release/integration

Conversation

@cx-aniket-shinde

Copy link
Copy Markdown
Collaborator

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Describe the purpose of this PR along with any background information and the impacts of the proposed change.

References

Include supporting link to GitHub Issue/PR number

Testing

Describe how this change was tested. Be specific about anything not tested and reasons why. If this solution has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Checklist

  • I have added documentation for new/changed functionality in this PR (if applicable).
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used

cx-aniket-shinde and others added 16 commits April 15, 2026 12:01
Adds the Cloud.md documentation file covering all essential sections:
Project Overview, Architecture, Repository Structure, Technology Stack,
Development Setup, Coding Standards, Project Rules, Testing Strategy,
Known Issues — plus recommended sections: External Integrations,
Deployment, Security & Access, Logging, and Debugging Steps.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
- Add FocusListener to project combo viewer
- When user clears project and clicks outside, branch combo is disabled
- Resets currentProjectId to empty when project field is cleared
- Preserves existing behavior for all other scenarios

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
* Fix AST-136023: Route authentication logs to Eclipse Error Log

Replace SLF4J log calls in Authenticator.doAuthentication() with
CxLogger so auth success/failure messages appear in .metadata/.log
and the Eclipse Error Log UI instead of being silently dropped.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-136023: Update unit tests to verify CxLogger static calls

Replace SLF4J mockLogger verification with MockedStatic<CxLogger>
to match the updated Authenticator.doAuthentication() which now
routes log output through CxLogger instead of the SLF4J instance.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Refactor AST-136023: Use String.format for authentication status log message

Replace string concatenation (AUTH_STATUS + cxValidateOutput) with
String.format(PluginConstants.INFO_AUTHENTICATION_STATUS, cxValidateOutput)
to be consistent with the error logging pattern. Updated the unit test
assertion to verify the formatted string accordingly.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
* Fix AST-136035: Clear detail panels on severity filter change; fix scan ID combo overflow

- Hide resultViewComposite and attackVectorCompositePanel when filter changes
  so the description and attack vector windows no longer show stale content
- Replace fixed widthHint=520 on scan ID combo with SWT.FILL/grabExcess layout
  so the combo is always visible without needing to maximize the window

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-136035: Clear right panels only when displayed item's severity is filtered out

Previously, toggling any severity filter always hid the description and
attack vector panels. Now the panels are only cleared when the currently
displayed item belongs to a severity that was just disabled. If the item's
severity is still active, the panels stay visible.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-136035: Preserve tree expansion state when severity filter changes

- Capture expanded elements before clearing the model so the snapshot
  is accurate when restoring after refresh
- Pass expand=true for FILTER_CHANGED (keep GET_RESULTS at false) so
  previously expanded group nodes are restored after filtering instead
  of collapsing the entire tree

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
* Fix AST-137779: Truncate long custom state names in filter menu and triage combo

Custom states with very long names caused the state filter dropdown menu
to expand across the entire screen. Fix truncates display text to 50 chars
(with trailing "...") in both the state filter MenuItem and the triage
state ComboViewer LabelProvider. The full state name is still used
internally for filtering and triage submission.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* Fix AST-137779: Guard against null getResults() in cxProjectMatchesWorkspaceProject

Results.getResults() can return null when no results have been loaded yet
(e.g. fresh IDE session before any scan is imported). The prior check only
guarded against a null Results object, causing an NPE on the first click
of the Start Scan button and preventing scans from running.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…RL not set) (#250)

The notify job references secrets.CXONE_SCAN_WEBHOOK_URL which does not
exist in this repo or at org level, causing the step to fail silently.

Ref: https://checkmarx.atlassian.net/browse/CISO-920
Ref: https://checkmarx.atlassian.net/browse/CISO-815
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: stepsecurity-app[bot] <188008098+stepsecurity-app[bot]@users.noreply.github.com>
@stepsecurity-app

Copy link
Copy Markdown
Contributor

Security Policy Alert: Actions Policy Violation

This workflow run has been blocked by StepSecurity's actions policy.

Disallowed Actions:

  • timonvs/pr-labeler-action@8b99f404a073744885d8021d1de4e40c6eaf38e2

To fix this issue, please modify the workflow to use only allowed actions. Contact your organization administrator to request changes to the allowed actions list if needed.

For more information, see StepSecurity's Actions Policy documentation.

Comment thread .claude/settings.local.json Outdated
@@ -0,0 +1,9 @@
{

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why we have added this file ?

@cx-anurag-dalke cx-anurag-dalke left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok

@cx-nisan-benabu cx-nisan-benabu merged commit f54c10c into main Jun 25, 2026
9 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants