OWASP/Nest

Repositories static sitemap lastmod always uses current time instead of latest repository update

オープン

#5,259 opened on 2026/07/20

 (2 件のコメント) (0 件のリアクション) (0 人の担当者)Python (651 件のフォーク)auto 404
good first issue

Repository metrics

Stars
 (412 個のスター)
PR merge metrics
 (平均マージ 2d 12h) (30d で 128 merged PRs)

説明

Describe the bug

StaticSitemap.lastmod (backend/src/apps/sitemap/views/static.py) maps each static route to a model so it can compute lastmod from that model's most recent updated_at. The /repositories route is listed in BaseSitemap.STATIC_ROUTES but is missing from the path_to_model mapping, so it falls through to the datetime.now(UTC) fallback that is meant for unknown paths.

As a result, the /repositories entry in the static sitemap reports the current time as its lastmod on every regeneration, instead of the latest repository update like the other seven routes.

To Reproduce

Steps to reproduce the behavior:

  1. Generate the static sitemap.
  2. Compare the <lastmod> value for /repositories against /chapters, /projects, etc.
  3. /repositories shows the regeneration timestamp, while the other routes show their model's latest updated_at.

Expected behavior

/repositories should derive its lastmod from the most recently updated Repository (Repository.objects.aggregate(Max("updated_at"))), consistent with the other content routes. The datetime.now(UTC) fallback is only intended for paths that have no corresponding model (the existing test covers this with /unknown-path).

Additional context

The fix is to add "/repositories": Repository to the path_to_model dict (and import the model). A test asserting that every STATIC_ROUTES path maps to a model would prevent this from regressing.

Are you going to work on fixing this?

  • Yes
  • No

コントリビューターガイド