Add MergeRequests::RiskAssessment and RiskOutcome models
What does this MR do and why?
Adds the MergeRequests::RiskAssessment and MergeRequests::RiskOutcome ActiveRecord models backing the merge_requests_risk_assessments and merge_requests_risk_outcomes tables introduced in !249134 (merged).
MergeRequests::RiskAssessmentbelongs tomerge_requestand has manyrisk_outcomes.MergeRequests::RiskOutcomebelongs torisk_assessment.- Adds
MergeRequests.table_name_prefix(app/models/merge_requests.rb), following the Rails convention already used for other namespaced models in this codebase, so the two new models don't need an explicitself.table_name. - Adds
JsonSchemaValidatorcoverage for theclassification,signal_breakdown, andevidenceJSONB columns, with permissive type-only schemas since the payload shape isn't finalized until later phases. app/models/concerns/populates_sharding_key.rbgains a new opt-inpresence:keyword onpopulate_sharding_key. When passed, it additionally declaresvalidates <attr>, presence: true. It defaults tofalse, so the 17 existing callers elsewhere in the codebase are unaffected.
Both models derive project_id through populate_sharding_key rather than requiring callers to set it: MergeRequests::RiskAssessment sources it from merge_request, and MergeRequests::RiskOutcome sources it from risk_assessment. Both pass presence: true, since project_id is NOT NULL in both tables - this surfaces a missing value as an application-level validation error instead of a database failure on save.
References
Part of &23131 (Phase 1)
Resolves #609302 (closed)
Screenshots or screen recordings
Not applicable - no UI changes.
How to set up and validate locally
- Pull this branch and run
bundle exec rails db:migrate. - Run the model specs:
bundle exec rspec spec/models/merge_requests/risk_assessment_spec.rb spec/models/merge_requests/risk_outcome_spec.rb - Run
bundle exec rspec spec/models/merge_request_spec.rbto confirm thehas_one :risk_assessmentassociation.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.