Skip to content

fix[backend](incident): add alert existence verification - #2828

Open
AlexSanchez-bit wants to merge 1 commit into
v11from
backlog/v11_incident_alert_verification
Open

AlexSanchez-bit wants to merge 1 commit into
v11from
backlog/v11_incident_alert_verification

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit
AlexSanchez-bit requested a review from a team October 5, 2026 14:23
@AlexSanchez-bit AlexSanchez-bit linked an issue Oct 5, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./utmstack-collector:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37
     - google.golang.org/api: v0.299.0 → v0.300.0

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.1
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.0
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/alerts:
     - github.com/threatwinds/go-sdk: v1.1.36 → v1.1.37
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/inputs:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/modules-config:
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.0
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.1
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37
     - google.golang.org/api: v0.299.0 → v0.300.0

  📁 ./plugins/config:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/crowdstrike:
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./agent:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./as400:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

  📁 ./as400/updater:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.37

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

✅ AI review — Approved with warnings

Only minor (medium/low) issues were found. They won't block the merge, but consider addressing them.

⚠️ architecture (silas-1.7-pro) — non-blocking warnings

Summary: Service-layer alert-existence validation is appropriate, but generic exception wrapping and newly stricter incident endpoints may affect API compatibility.

  • medium backend/src/main/java/com/park/utmstack/service/incident/UtmIncidentService.java:297 — Catching Exception and rethrowing RuntimeException hides the root cause and can map alert/OpenSearch errors to generic failures; preserve or translate to a specific service exception.
  • low backend/src/main/java/com/park/utmstack/service/incident/UtmIncidentService.java:141 — Adding existence checks changes accepted request behavior for incident creation/addition; verify this does not break public clients or requires compatibility handling.

⚠️ bugs (silas-1.7-pro) — non-blocking warnings

Summary: No blocking bugs; minor error-handling and user-facing message issues in the new alert existence validation.

  • low backend/src/main/java/com/park/utmstack/service/incident/UtmIncidentService.java:313 — User-facing error message exposes the internal backend term 'OpenSearch'. Reproduce by calling createIncident or addAlertsIncident with an alert ID that is not present in OpenSearch. Change the message to something like 'The following alert IDs were not found'.
  • low backend/src/main/java/com/park/utmstack/service/incident/UtmIncidentService.java:320 — The wrapped RuntimeException does not preserve the original exception as the cause, so the underlying stack trace is lost. Reproduce when utmAlertService.getAlertsByIds throws an exception such as an OpenSearch or network error. Use new RuntimeException(msg, e) or log the full exception.

⚠️ security (silas-1.7-pro) — non-blocking warnings

Summary: New alert existence validation can rethrow wrapped exception messages that may disclose internal error details.

  • low backend/src/main/java/com/park/utmstack/service/incident/UtmIncidentService.java:319 — The broad catch block includes e.getMessage() in the wrapped RuntimeException, which may expose internal OpenSearch or service failure details to end users. Log the full exception server-side only and throw a generic client-facing error.

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

incident creation alert existence validation

1 participant