Draft: BL Security Analyzer: monolith integration (ingestion, Inventory/Config, foundational-flow registration)
WIP integration prototype — do not merge. Pairs with the engine MR gitlab-org/…/ai-assist!6322.
Monolith-side integration for the BL (Business Logic) Security Analyzer — epic gitlab-org&22436, comp #603666. Full stack (20 commits, rebased clean onto current master):
- Security ingestion: recognize
duo_workflowagentic-analyzer workload pipelines; declarativeartifacts:reportson workload definitions;Security::AgenticAnalyzerat default-branch HEAD. - Foundational-flow registry:
security_scan/v1+bl_security/v1(security_report_artifacts, pipeline_hooks trigger filter, ultimate_only). - Security Inventory + Configuration: default-branch first-class recognition, Configuration Profiles, Business-Logic Tool-Coverage badge, coherent enablement UX (
SetBusinessLogicScanmutation/service). - Policy integration (scan-execution + scan-result see agentic findings); MR security widget head resolution; partial-scan handling;
analyzer_typeenum; audit event + permission declaration (enable_business_logic_scangranular-token authz).
Status (honest)
The engine + integration run end-to-end at scale through the product path → Vulnerability Report (see ai-assist!6322). Detection quality is NOT yet shippable: on a real repo (gitea) recall 0/10 + precision 0/9 — the reviewer does not yet trace mature-codebase authz (middleware chains + in-handler predicates). This branch preserves the integration cleanly on current master; it is WIP, not a merge candidate. Full eval + root-cause trail in the assistant workspace.
NB: the added authz request spec satisfies permissions-verify statically but was not executed locally (rspec not in pre-push); CI will validate.