VR appearing for non-SAST vulnerabilities
Summary
"Resolve with AI" should not be appearing for non-SAST vulnerabilities. The frontend uses the glAbilities.resolveVulnerabilityWithAi boolean value to either hide or show the button.
- For non-SAST =
glAbilities.resolveVulnerabilityWithAi = false - For SAST =
glAbilities.resolveVulnerabilityWithAi = true
Currently in production, it is outputting the incorrect value
Note: Vulnerability data aiResolutionAvailable is working fine
Note: on the vulnerability data, we also have access to aiResolutionAvailable, which controls whether the vulnerability can be AI resolved (whether it's a high CWE or not). That is working as expected:
| Non-SAST | SAST (not high confidence) | SAST (high confidence) |
|---|---|---|
![]() |
![]() |
![]() |
Steps to reproduce
Example Project
- Non-SAST: https://gitlab.com/gitlab-examples/security/security-reports/-/security/vulnerabilities/77167618
- SAST (High CWE): https://gitlab.com/gitlab-org/security-products/oxeye/dogfooding/generic/oxeye-rulez/-/security/vulnerabilities/128168629
- SAST: https://gitlab.com/gitlab-org/security-products/oxeye/dogfooding/generic/oxeye-rulez/-/security/vulnerabilities/128168727
What is the current bug behavior?
"Resolve with AI" should not be appearing for non-SAST vulnerabilities.
What is the expected correct behavior?
"Resolve with AI" should be hidden non-SAST vulnerabilities.
Relevant logs and/or screenshots
Output of checks
Results of GitLab environment info
Expand for output related to GitLab environment info
(For installations with omnibus-gitlab package run and paste the output of: `sudo gitlab-rake gitlab:env:info`) (For installations from source run and paste the output of: `sudo -u git -H bundle exec rake gitlab:env:info RAILS_ENV=production`)
Results of GitLab application Check
Expand for output related to the GitLab application check
(For installations with omnibus-gitlab package run and paste the output of:
sudo gitlab-rake gitlab:check SANITIZE=true)(For installations from source run and paste the output of:
sudo -u git -H bundle exec rake gitlab:check RAILS_ENV=production SANITIZE=true)(we will only investigate if the tests are passing)



