Skip to content

containerprofile: let one annotation follow the newest report - #49

Merged
ConstanzeTU merged 1 commit into
feat/rogue-artifactsfrom
feat/governance-transitions
Sep 20, 2026
Merged

ConstanzeTU merged 1 commit into
feat/rogue-artifactsfrom
feat/governance-transitions

Conversation

@ConstanzeTU

Copy link
Copy Markdown

Chunk annotations fold into the consolidated ContainerProfile first-write-wins, so every key freezes at whatever the first chunk carried. kubescape.io/timeline is a running record the agent rewrites in full on every chunk; this exempts that one key and keeps the value whose last entry is the latest, independent of merge order. Empty or unparsable values never replace a parsable one. Every other annotation keeps first-write-wins.

Tests: TestNewerTimeline (table), TestMergeContainerProfileTS_TimelineIsOrderIndependent (both merge orders), _TimelineAcrossBatches, _TimelineOnNilAnnotations, _OtherAnnotationsStayFirstWriteWins. The order-independence test fails on the previous assign-in-order form.

Chunk annotations fold into the consolidated profile first-write-wins, which
freezes every key at whatever the first chunk carried. kubescape.io/timeline
is a running record the agent rewrites in full on every chunk, so the value
whose last entry is the latest wins, independent of the order chunks are
merged in. An empty or unparsable value never replaces a parsable one; every
other annotation keeps first-write-wins.
@ConstanzeTU
ConstanzeTU merged commit cfe01a9 into feat/rogue-artifacts Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant