Prevent report ingestion readiness from blocking on dormant jobs

What does this MR do and why?

Prevent security report ingestion readiness from being blocked by dormant jobs that never run.

Changes

  • Replace all_security_jobs_complete? with security_reports_ready_for_ingestion?
  • Evaluate only report-producing security jobs that are active or completed
  • Exclude dormant created and manual jobs from readiness checks
  • Preserve synchronization with security scan processing before ingestion begins
  • Include CycloneDX/SBOM-producing jobs when determining ingestion readiness
  • Restrict scan-processing checks to builds that actually produced security reports

The previous readiness check required all security jobs in the pipeline hierarchy to complete, even when some jobs remained in created or manual states and never produced reports. This could indefinitely block security and SBOM report ingestion despite all available reports being ready.

This change shifts readiness evaluation from job completion to report availability. Ingestion now proceeds once all relevant report-producing jobs have either completed or are no longer expected to produce reports, while still waiting for associated security scan processing to finish.

As a result, dormant jobs no longer prevent ingestion, and report processing remains correctly synchronized across parent and child pipelines.

References

Screenshots or screen recordings

Before After

How to set up and validate locally

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Ugo Nnanna Okeadu

Merge request reports

Loading
Loading