Dismissals persist after merge across contexts
What does this MR do and why?
This fixes a regression caused by vulnerabilities across contexts. When you dismiss a vulnerability on a merge request that targets a tracked context branch, the metadata is not persisted correctly after merge.
There is a baked-in assumption that was overlooked when originally covering this - that the UUID used for lookup is safe to always be the version without the tracked context. This worked, because the default branch didn't ever use the tracked context for UUID computation, but it now does for new projects.
The fix is to mirror the placeholder Vulnerability record onto the target branch with a UUID corresponding to that target. This is the correct/complete fix: if you are merging from a tracked context onto another tracked context then your dismissal during an MR should update two records - one for the target tracked context and one for the source tracked context.
How to set up and validate locally
- Check out this branch.
- Create a project with some vulnerabilities, ingest them on the default branch.
- Make a new branch - do not track this branch.
- Edit the branch to introduce another vulnerability.
- Open a merge request.
- Go to the pipeline and dismiss that vulnerability.
- Merge the merge request.
- Verify that the vulnerability report now shows that new vulnerability from 4. with the relevant dismissal.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.