Add MergeRequests::RiskAssessment and RiskOutcome models

What does this MR do and why?

Adds the MergeRequests::RiskAssessment and MergeRequests::RiskOutcome ActiveRecord models backing the merge_requests_risk_assessments and merge_requests_risk_outcomes tables introduced in !249134 (merged).

  • MergeRequests::RiskAssessment belongs to merge_request and has many risk_outcomes.
  • MergeRequests::RiskOutcome belongs to risk_assessment.
  • Adds MergeRequests.table_name_prefix (app/models/merge_requests.rb), following the Rails convention already used for other namespaced models in this codebase, so the two new models don't need an explicit self.table_name.
  • Adds JsonSchemaValidator coverage for the classification, signal_breakdown, and evidence JSONB columns, with permissive type-only schemas since the payload shape isn't finalized until later phases.
  • app/models/concerns/populates_sharding_key.rb gains a new opt-in presence: keyword on populate_sharding_key. When passed, it additionally declares validates <attr>, presence: true. It defaults to false, so the 17 existing callers elsewhere in the codebase are unaffected.

Both models derive project_id through populate_sharding_key rather than requiring callers to set it: MergeRequests::RiskAssessment sources it from merge_request, and MergeRequests::RiskOutcome sources it from risk_assessment. Both pass presence: true, since project_id is NOT NULL in both tables - this surfaces a missing value as an application-level validation error instead of a database failure on save.

References

Part of &23131 (Phase 1)

Resolves #609302 (closed)

Screenshots or screen recordings

Not applicable - no UI changes.

How to set up and validate locally

  1. Pull this branch and run bundle exec rails db:migrate.
  2. Run the model specs:
    bundle exec rspec spec/models/merge_requests/risk_assessment_spec.rb spec/models/merge_requests/risk_outcome_spec.rb
  3. Run bundle exec rspec spec/models/merge_request_spec.rb to confirm the has_one :risk_assessment association.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Wanderson Policarpo

Merge request reports

Loading
Loading