Add license, vulnerability, and malicious rule builders (2/4)

What does this MR do?

Second of a four-MR stack that splits the dependency-firewall (DFW) rule-builder policy editor UI into layers that can be reviewed and merged one at a time. See dfw-rule-builder-mr1-substrate for the full stack overview and the feature-flag rollout plan.

Builds on the shared widgets and constants from the previous MR with the three rule-type builders and the pure helper functions they share for reading, writing, and toggling a rule's allow/deny list and exceptions:

  • dependency_firewall/utils.js: buildDefaultRuleForType, getRuleList/getRuleListKey, toggleRuleListKey, and the exceptions-to-textarea conversion helpers used by all three builders
  • license_rule_builder.vue: allow or deny by SPDX license name, using a searchable multi-select backed by the app's SPDX license catalogue
  • vulnerability_rule_builder.vue: allow or deny by severity threshold
  • malicious_rule_builder.vue: always-deny rule sourced from the malicious packages feed

None of this is referenced anywhere yet, so merging this MR alone changes no runtime behavior.

Feature flag / rollout

Same as MR1: gated behind dependency_firewall_phase2, which is checked only in the final MR of this stack. This MR is an inert addition until that MR merges and the flag is enabled.

MR stack

  • Previous: dfw-rule-builder-mr1-substrate (target: master)
  • You are here: dfw-rule-builder-mr2-rule-builders (target: dfw-rule-builder-mr1-substrate)
  • Next: dfw-rule-builder-mr3-orchestration (target: this branch)
  • Then: dfw-rule-builder-mr4-wiring (adds the dependency_firewall_phase2 gate)

Screenshots or demos

No rendered UI change from this MR alone.

image__31_ image__30_ image__29_ image__28_ image__27_ image__26_ image__25_

Full flow testing: !251591 (merged)

How to set up and validate locally

  1. Checkout dfw-rule-builder-mr2-rule-builders
  2. yarn jest ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/utils_spec.js ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/rule/license_rule_builder_spec.js ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/rule/vulnerability_rule_builder_spec.js ee/spec/frontend/security_orchestration/components/policy_editor/dependency_firewall/rule/malicious_rule_builder_spec.js

References

https://gitlab.com/gitlab-org/gitlab/-/work_items/616534+s

Edited by Hannah Baker

Merge request reports

Loading
Loading