Loading
Add auto resolve JSON schemas
What does this MR do and why?
Adds JSON schemas for four new security profile configuration types: SAST VR, SAST FP, SD FP, and vulnerability enrichment.
Properties and limits come from the this table. Properties whose type or shape is still undefined (vulnerability_context_metadata, business_context, target_branch, the percentage form of FP confidence) are left out for now.
Changelog: added
EE: true
Schema values added:
sast_vulnerability_resolution
| Property | Type | Allowed values | Limits |
|---|---|---|---|
severity_level |
enum | info, unknown, low, medium, high, critical |
Minimum threshold |
cwe_classes |
array of string | CWE-<digits> |
up to 50 items, each ^CWE-\d{1,5}$ |
run_mode |
enum | manual, auto |
|
false_positive_confidence |
enum | likely_false_positive, likely_not_false_positive |
sast_false_positive
| Property | Type | Allowed values | Limits |
|---|---|---|---|
severity_level |
enum | info, unknown, low, medium, high, critical |
Minimum threshold |
cwe_classes |
array of string | CWE-<digits> |
50 items, each ^CWE-\d{1,5}$ |
run_mode |
enum | manual, auto |
secret_detection_false_positive
| Property | Type | Allowed values | Limits |
|---|---|---|---|
run_mode |
enum | manual, auto |
vulnerability_enrichment
| Property | Type | Allowed values | Limits |
|---|---|---|---|
severity_level |
enum | info, unknown, low, medium, high, critical |
Minimum threshold |
run_mode |
enum | manual, auto |
All four set additionalProperties: false, so unknown keys are rejected.
Related issue
[Backend] Add JSON schemas for Auto resolve con... (#618777 - closed) • Gal Katz
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Gal Katz