Restrict new validity checks to GSS scanner findings

What does this MR do and why?

Restricts the new Secret Detection validity checks:

To findings whose identifiers include the GitLab Secret Scanning for Source Code (GSS) rule identifier types:

  • gitlab_secret_scanner_rule_id (current one)
  • gitlab_secrets_scanner_rule_id (older, used before the analyzer's v0.16.0 rename).

Findings from the gitleaks-based analyzer will not have a validity status for these token types.

Slack (!248113 (closed)) stays parked due to structure inconsistency.

The new restricted_to_gss_scanner attribute is added to both:

  • Security::SecretDetection::PartnerTokens::Registry: true for the new checks, false for the pre-existing ones.
  • Security::SecretDetection::TokenLookupService: false for all current GitLab token types, so future checks can opt in.

Resolves #612117 (closed).

MR acceptance checklist

I have evaluated this MR against the MR acceptance checklist.

Edited by Ahmed Hemdan

Merge request reports

Loading
Loading