Skip to content

AIML-1463 Remove false lastSeen signal from list_applications_by_cve - #269

Merged
ChrisEdwards merged 4 commits into
mainfrom
AIML-1463-remove-false-lastseen-notice
Sep 24, 2026
Merged

ChrisEdwards merged 4 commits into
mainfrom
AIML-1463-remove-false-lastseen-notice

Conversation

@ChrisEdwards

@ChrisEdwards ChrisEdwards commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

AIML-1463

Why the change

list_applications_by_cve told agents that every affected app "has never been observed running" because TeamServer's CVE endpoint always sends last_seen: 0 (TS-42938), and our code read that zero as a meaningful signal.

Special things to note

  • Breaking change to published artifact. App.lastSeen is removed from contrast-mcp-core. The aiml-services bump is tracked in child bead mcp-074d9 (same Jira).
  • Re-adding lastSeen later. When TS-42938 ships with real data, lastSeen comes back as a nullable field (tracked in bead mcp-ra7w).
  • Code owners switch. .github/CODEOWNERS now names @Contrast-Security-OSS/platform-developers in place of @Contrast-Security-OSS/aiml-developers. @ChrisEdwards stays.

Change outline

The false signal flowed through three pieces. All three are removed:

 App.java (data model)
   appId
   name
   firstSeen        # ← has real values, kept
-  lastSeen         # ← always 0 from this endpoint, removed
   lastReset
   servers
 ListApplicationsByCveTool.java
   @Tool description:
-    "lastSeen and server status reflect last-known agent reports..."
+    "Use search_applications for application lastSeenAt and
+     search_servers for current server state."

   listApplicationsByCve():
     fetchCveData()
     if (apps empty) return
-    noticeNeverObservedApps(apps)    # ← always fired, always wrong
     enrichWithClassUsage(apps)
     return

-  noticeNeverObservedApps(apps):     # ← deleted entirely
-    filter apps where lastSeen == 0
-    emit "never been observed running: <app names>"

Three test layers now enforce the removal:

 Unit test    (ToolTest)       → deserializes {last_seen: 0}, asserts field absent from JSON output
 Parity test  (LocalParity)   → same assertions through the local stdio code path
 Integration  (ToolIT)        → same assertions against live TeamServer response

ChrisEdwards and others added 2 commits September 23, 2026 14:39
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
@ChrisEdwards
ChrisEdwards merged commit b00231a into main Sep 24, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants