Allow additional properties in malware advisory identifiers
Allow additional properties on items in the malware advisory identifiers JSON schema.
Why
identifiers is copied verbatim from the GLAM v3 NDJSON feed. With
additionalProperties: false on each item, any new key GLAM adds
inside an identifier fails schema validation for every advisory
carrying it. MalwareAdvisoryIngestionTask skips invalid records
instead of aborting the batch, so those advisories would be silently
dropped from pm_malware_advisories with no ingestion-level error,
until the schema itself is updated in a later release.
What changed
ee/app/validators/json_schemas/pm_malware_advisory_identifiers.json:items.additionalPropertiesset totrue.ee/spec/models/package_metadata/malware_advisory_spec.rb: updated the corresponding example to expect validity instead of an error.
Risk
Low. Required keys (type, name, value) are still enforced, and
the payload stays bounded by size_limit: 8.kilobytes, maxItems: 64,
and the per-field maxLength caps. Unknown keys are stored as-is in
the jsonb column and nothing reads them.