Add 'details' object to ruby files
What does this MR do and why?
According to this task, this MR is one of the development stages.
When gitlab found a vulnerability in 'mr changes page' there is a GraphQL query that brings all the details of the vulnerability.
In this MR:
- I have added a
detailsobject to ruby files. - moving
ee/app/assets/javascripts/security_dashboard/graphql/fragments/vulnerability_detail.fragment.graphqlto a shared folder:app/assets/javascripts/graphql_shared/fragments/vulnerability_detail.fragment.graphql.
Note: Because of backward compatibility issue, in the next MR (that will be in the next milestone) I will add details to GraphQL file.
MR acceptance checklist
Please evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Screenshots or screen recordings
Screenshots are required for UI changes, and strongly recommended for all other merge requests.
| Before | After |
|---|---|
![]() |
![]() |
How to set up and validate locally
- Upload a GitLab Ultimate license
- Create an empty project
- Go to your locally project and edit with web IDE
- Create a new file called:
gl-sast-report.jsonand copy the content from here: gl-sast-report.json - Create a new file
.gitlab-ci.ymland pasted this content: gitlab-ci.yml - Create a new folder called
appand a new file inside calledapp.pyand pasted this content: app.py - Create a new MR
- Go into 'Changes' in your MR and you will see the detected vulnerability using shapes next to the specific rows.
- Open
Inspect element->Network-> findgraphqlAPI request withoperationName: "getMRCodequalityAndSecurityReports"->Preview-> Check thatdetailsobject exist indata.project.mergeRequest.sastReport.report.added[0]
Numbered steps to set up and validate the change are strongly suggested.
Related to #482849 (closed) and #478469 (closed)
Edited by Chen Charnolevsky

