OWASP/Nest

Repositories static sitemap lastmod always uses current time instead of latest repository update

Open

#5,259 opened on Jul 20, 2026

 (2 comments) (0 reactions) (0 assignees)Python (651 forks)auto 404
good first issue

Repository metrics

Stars
 (412 stars)
PR merge metrics
 (Avg merge 2d 12h) (128 merged PRs in 30d)

Description

Describe the bug

StaticSitemap.lastmod (backend/src/apps/sitemap/views/static.py) maps each static route to a model so it can compute lastmod from that model's most recent updated_at. The /repositories route is listed in BaseSitemap.STATIC_ROUTES but is missing from the path_to_model mapping, so it falls through to the datetime.now(UTC) fallback that is meant for unknown paths.

As a result, the /repositories entry in the static sitemap reports the current time as its lastmod on every regeneration, instead of the latest repository update like the other seven routes.

To Reproduce

Steps to reproduce the behavior:

  1. Generate the static sitemap.
  2. Compare the <lastmod> value for /repositories against /chapters, /projects, etc.
  3. /repositories shows the regeneration timestamp, while the other routes show their model's latest updated_at.

Expected behavior

/repositories should derive its lastmod from the most recently updated Repository (Repository.objects.aggregate(Max("updated_at"))), consistent with the other content routes. The datetime.now(UTC) fallback is only intended for paths that have no corresponding model (the existing test covers this with /unknown-path).

Additional context

The fix is to add "/repositories": Repository to the path_to_model dict (and import the model). A test asserting that every STATIC_ROUTES path maps to a model would prevent this from regressing.

Are you going to work on fixing this?

  • Yes
  • No

Contributor guide