Support multiple scan profiles in inventory bulk drawer

What does this MR do and why?

When the configurable_security_scan_profiles FF is enabled and a namespace has multiple profiles of the same scan type, the Security Inventory's bulk-edit drawer only offered the default profile for each scanner. This MR removes the gitlabRecommended: true filter from the Apollo query and adds per-row profile selection via GlCollapsibleListbox.

The table still renders one row per scan type. Each row tracks which profile is selected (defaulting to recommended), and when a scan type has multiple profiles, the Profile column becomes a listbox. Non-default selections update the payload sent to Apply profile to all and Preview profile. Once applied, the picker collapses to show the applied-profile link, matching single-profile row behavior.

This change gates the multi-profile UI per row based on profile count, so no FF plumbing to the frontend is needed. Existing single-profile tests remain unchanged. New specs cover: one row per scan type, listbox rendering, listbox selection, non-default labels, and picker collapse after apply.

Updated locale/gitlab.pot for two new strings: "Apply profile to all" and "Preview profile".

Note: configurable_security_scan_profiles gates only profile create/update on the backend. The resolver feeding availableSecurityScanProfiles has no FF check, so namespaces that already created custom profiles keep the multi-profile picker even after the flag is turned off. Rollback for this MR is a revert, not a flag flip.

References

Related to #609512 (closed)

This is 3 of 4 MRs planned for the areas flagged on that issue.

Screenshots or screen recordings

Before After
Screenshot 2026-08-11 at 15.29.56.png

How to set up and validate locally

  1. Enable the configurable_security_scan_profiles FF.
  2. Under a group, create at least one extra profile of the same scan type (see !247227 (merged) for setup).
  3. Open the Security Inventory, select a project or subgroup.
  4. Click Edit security scanners, and confirm: multi-profile scan types show a listbox.
  5. Selecting a non-default profile updates the button label and preview target.
  6. Clicking Apply profile to all collapses the row to the applied-profile link with only Disable for all remaining.
Edited by Chen Charnolevsky

Merge request reports

Loading
Loading