Allow additional properties in malware advisory identifiers

Allow additional properties on items in the malware advisory identifiers JSON schema.

Why

identifiers is copied verbatim from the GLAM v3 NDJSON feed. With additionalProperties: false on each item, any new key GLAM adds inside an identifier fails schema validation for every advisory carrying it. MalwareAdvisoryIngestionTask skips invalid records instead of aborting the batch, so those advisories would be silently dropped from pm_malware_advisories with no ingestion-level error, until the schema itself is updated in a later release.

What changed

  • ee/app/validators/json_schemas/pm_malware_advisory_identifiers.json: items.additionalProperties set to true.
  • ee/spec/models/package_metadata/malware_advisory_spec.rb: updated the corresponding example to expect validity instead of an error.

Risk

Low. Required keys (type, name, value) are still enforced, and the payload stays bounded by size_limit: 8.kilobytes, maxItems: 64, and the per-field maxLength caps. Unknown keys are stored as-is in the jsonb column and nothing reads them.

Edited by Orin Naaman

Merge request reports

Loading
Loading