OverrideUuidsService picks from default branch
What does this MR do and why?
In very rare cases, the context-unaware UUID for a vulnerability can differ between branches. The root cause of this divergence has been fixed but the fix suffers from a rare synchronisation problem.
When the OverrideUuidsService runs to calibrate the context-unaware UUID against a previously-seen version of this vulnerabilitiy, it picks the first match of the vulnerability regardless of what tracked branch it is found on. This is logically correct as the UUID should be the same on any branch, and if it's not then we should override to the same value every time, self correcting as pipelines are run. The second half of the previous statement is where the syncrhonisation issue lies.
When we query for previously-seen vulnerabilities we don't order the query results. This is the synchronisation issue. This MR instead picks the UUID value of the matching record on the default branch - providing a stable ground truth to base off of.
References
Fixes: https://gitlab.com/gitlab-com/request-for-help/-/work_items/5241 (internal)
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.