Add auto resolve JSON schemas

What does this MR do and why?

Adds JSON schemas for four new security profile configuration types: SAST VR, SAST FP, SD FP, and vulnerability enrichment.

Properties and limits come from the this table. Properties whose type or shape is still undefined (vulnerability_context_metadata, business_context, target_branch, the percentage form of FP confidence) are left out for now.

Changelog: added
EE: true

Schema values added:

sast_vulnerability_resolution

Property Type Allowed values Limits
severity_level enum info, unknown, low, medium, high, critical Minimum threshold
cwe_classes array of string CWE-<digits> up to 50 items, each ^CWE-\d{1,5}$
run_mode enum manual, auto
false_positive_confidence enum likely_false_positive, likely_not_false_positive

sast_false_positive

Property Type Allowed values Limits
severity_level enum info, unknown, low, medium, high, critical Minimum threshold
cwe_classes array of string CWE-<digits> 50 items, each ^CWE-\d{1,5}$
run_mode enum manual, auto

secret_detection_false_positive

Property Type Allowed values Limits
run_mode enum manual, auto

vulnerability_enrichment

Property Type Allowed values Limits
severity_level enum info, unknown, low, medium, high, critical Minimum threshold
run_mode enum manual, auto

All four set additionalProperties: false, so unknown keys are rejected.

[Backend] Add JSON schemas for Auto resolve con... (#618777 - closed) • Gal Katz

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Gal Katz

Merge request reports

Loading
Loading