Draft: Add internal tracking for SARIF reports ingestion

What does this MR do and why?

Introduces the ingest_sarif_report Internal Event, emitted once per SARIF report artifact that is parsed and ingested with no parser errors, so we can track SARIF ingestion volume over time.

SARIF artifacts can fan out into multiple typed scans so the resulting Security::Scan rows might never be scan_type: sarif. The event is fired from Security::StoreGroupedScansService, the one layer that both knows file_type == 'sarif' and still holds the artifact together with its full fan-out of typed reports.

Changelog: added
EE: true

Add sarif ingestion metrics (#604719 - closed) • Gal Katz • 19.5

How to set up and validate locally

  1. Run a pipeline with a SARIF report. Example project.

  2. After the pipeline finishes and the report is ingested, confirm the count increments in the console:

    d = Gitlab::Usage::MetricDefinition.definitions['counts.count_total_ingest_sarif_report']
    Gitlab::Usage::Metric.new(d).send(:instrumentation_object).value
    # => increases by 1 for each SARIF report ingested with no parser errors

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading