OWASP/Nest

Repositories static sitemap lastmod always uses current time instead of latest repository update

Offen

#5.259 geöffnet am 20.07.2026

 (2 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)Python (651 Forks)auto 404
good first issue

Repository-Metriken

Stars
 (412 Sterne)
PR-Merge-Metriken
 (Durchschn. Merge 2T 12h) (128 gemergte PRs in 30 T)

Beschreibung

Describe the bug

StaticSitemap.lastmod (backend/src/apps/sitemap/views/static.py) maps each static route to a model so it can compute lastmod from that model's most recent updated_at. The /repositories route is listed in BaseSitemap.STATIC_ROUTES but is missing from the path_to_model mapping, so it falls through to the datetime.now(UTC) fallback that is meant for unknown paths.

As a result, the /repositories entry in the static sitemap reports the current time as its lastmod on every regeneration, instead of the latest repository update like the other seven routes.

To Reproduce

Steps to reproduce the behavior:

  1. Generate the static sitemap.
  2. Compare the <lastmod> value for /repositories against /chapters, /projects, etc.
  3. /repositories shows the regeneration timestamp, while the other routes show their model's latest updated_at.

Expected behavior

/repositories should derive its lastmod from the most recently updated Repository (Repository.objects.aggregate(Max("updated_at"))), consistent with the other content routes. The datetime.now(UTC) fallback is only intended for paths that have no corresponding model (the existing test covers this with /unknown-path).

Additional context

The fix is to add "/repositories": Repository to the path_to_model dict (and import the model). A test asserting that every STATIC_ROUTES path maps to a model would prevent this from regressing.

Are you going to work on fixing this?

  • Yes
  • No

Contributor Guide