close old findings: don't overwrite mitigated timestamp #12204
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Sometimes (as in #12168) findings get mitigated during import because the finding is mitigated in the scan report. That scan report can also contain a
mitigated
timestamp. Currently DefectDojo always overwrites this timestamp during reimport. This PR changes that to no overwrite it.This is just a quickfix as the root cause is that the findings are already closed and don't need to be seen as old findings are they are still in the report. We'll work on that in a later PR.