OWASP/Nest

Repositories static sitemap lastmod always uses current time instead of latest repository update

開放

#5,259 建立於 2026年7月20日

 (2 則留言) (0 個反應) (0 位負責人)Python (651 個分叉)auto 404
good first issue

倉庫指標

星標
 (412 顆星)
PR 合併指標
 (平均合併 2天 12小時) (30 天內合併 128 個 PR)

描述

Describe the bug

StaticSitemap.lastmod (backend/src/apps/sitemap/views/static.py) maps each static route to a model so it can compute lastmod from that model's most recent updated_at. The /repositories route is listed in BaseSitemap.STATIC_ROUTES but is missing from the path_to_model mapping, so it falls through to the datetime.now(UTC) fallback that is meant for unknown paths.

As a result, the /repositories entry in the static sitemap reports the current time as its lastmod on every regeneration, instead of the latest repository update like the other seven routes.

To Reproduce

Steps to reproduce the behavior:

  1. Generate the static sitemap.
  2. Compare the <lastmod> value for /repositories against /chapters, /projects, etc.
  3. /repositories shows the regeneration timestamp, while the other routes show their model's latest updated_at.

Expected behavior

/repositories should derive its lastmod from the most recently updated Repository (Repository.objects.aggregate(Max("updated_at"))), consistent with the other content routes. The datetime.now(UTC) fallback is only intended for paths that have no corresponding model (the existing test covers this with /unknown-path).

Additional context

The fix is to add "/repositories": Repository to the path_to_model dict (and import the model). A test asserting that every STATIC_ROUTES path maps to a model would prevent this from regressing.

Are you going to work on fixing this?

  • Yes
  • No

貢獻者指南