Pub auto remediation support

Why are we doing this work

Pub is the standard package manager for the Dart and Flutter ecosystem. Extending auto-remediation to support Pub lets Dart/Flutter projects benefit from automatic MR creation for vulnerable dependency upgrades, the same way Ruby/Bundler and Java/Maven projects do today.

This is part of &19244 (Auto-remediation with automatic bumping of dependencies - GA).

Implementation plan

Package manager: pub (pubspec.yaml, pubspec.lock). Version bumping is handled by the dependabot-pub gem.

Updater

  • Add pub/Dockerfile - mirrors bundler/Dockerfile/maven/Dockerfile with ARG ECOSYSTEM=pub. Base image needs the Dart SDK since dependabot-pub invokes dart pub tooling at runtime
  • Add a pub build target to docker-bake.hcl
  • Add a release job in .gitlab/ci/jobs/release-ecosystems.yml
  • No Ruby code changes needed - PackageManager enum and EcosystemLoader already support pub

Orchestrator

No changes required. schema.json already lists pub as a valid package-manager value. Routing to the correct updater image is automatic.

GitLab (Rails)

  • scheduler_service.rb - add 'pub' to SUPPORTED_PACKAGE_MANAGERS
  • job_builder.rb - add a 'pub' => 'pub' entry to PACKAGE_MANAGER_MAPPING
  • doc/user/application_security/remediate/auto_remediation.md - add a Dart/Pub row to the supported package managers table

Non-functional requirements

  • Documentation: update auto_remediation.md to add Pub (pubspec.yaml, pubspec.lock) to the supported package managers table
  • Feature flag: gated behind existing dependency_management_auto_remediation flag - no new flag needed
  • Performance: no impact - Pub follows the same workload pattern as Bundler/Maven
  • Testing:
    • Updater: extend ecosystem_loader_spec.rb load table; add spec/fixtures/pub/ fixture project; add Pub contexts to file_fetcher_command_spec.rb, file_parser_command_spec.rb, file_updater_command_spec.rb
    • E2e: run the pub-updater container against a real GitLab project with a known vulnerable dependency and verify output.json and MR creation end-to-end

Verification steps

  1. Enable dependency_management_auto_remediation feature flag on a test project using Pub
  2. Ensure dependency scanning is enabled and producing results with at least one vulnerability that has a known fix version
  3. Run a pipeline and confirm an auto-remediation MR is created that bumps the vulnerable dependency in pubspec.yaml/pubspec.lock
  4. Confirm the MR title, description, and branch name follow the same format as Bundler/Maven MRs
  5. Merge the MR and confirm the vulnerability is resolved in the next pipeline scan
Edited by 🤖 GitLab Bot 🤖