Add license, vulnerability, and malicious rule builders (2/4)
What does this MR do?
Second of a four-MR stack that splits the dependency-firewall (DFW) rule-builder policy editor UI into layers that can be reviewed and merged one at a time. See dfw-rule-builder-mr1-substrate for the full stack overview and the feature-flag rollout plan.
Builds on the shared widgets and constants from the previous MR with the three rule-type builders and the pure helper functions they share for reading, writing, and toggling a rule's allow/deny list and exceptions:
dependency_firewall/utils.js:buildDefaultRuleForType,getRuleList/getRuleListKey,toggleRuleListKey, and the exceptions-to-textarea conversion helpers used by all three builderslicense_rule_builder.vue: allow or deny by SPDX license name, using a searchable multi-select backed by the app's SPDX license cataloguevulnerability_rule_builder.vue: allow or deny by severity thresholdmalicious_rule_builder.vue: always-deny rule sourced from the malicious packages feed
None of this is referenced anywhere yet, so merging this MR alone changes no runtime behavior.
Feature flag / rollout
Same as MR1: gated behind dependency_firewall_phase2, which is checked only in the final MR of this stack. This MR is an inert addition until that MR merges and the flag is enabled.
MR stack
- Previous: dfw-rule-builder-mr1-substrate (target:
master) - You are here:
dfw-rule-builder-mr2-rule-builders(target: dfw-rule-builder-mr1-substrate) - Next:
dfw-rule-builder-mr3-orchestration(target: this branch) - Then:
dfw-rule-builder-mr4-wiring(adds thedependency_firewall_phase2gate)
Screenshots or demos
No rendered UI change from this MR alone.
Full flow testing: !251591 (merged)
How to set up and validate locally
- Checkout
dfw-rule-builder-mr2-rule-builders yarn jest ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/utils_spec.js ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/rule/license_rule_builder_spec.js ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/rule/vulnerability_rule_builder_spec.js ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/rule/malicious_rule_builder_spec.js






