Add select all eligible for bulk AI vulnerability actions

What does this MR do and why?

Bulk AI actions in the Vulnerability Report ("Detect false positives" and "Resolve with AI") were limited to per row and current page selection. Running either flow across a whole project backlog meant paging through the report and checking every row by hand, even though the backend already supported whole project runs.

This MR adds a "Select all eligible" toggle to the selection banner. It only appears once one of the two bulk AI actions is chosen from the action dropdown, it is scoped to that action, and it does not select rows across pages. Toggling it on replaces the "N Selected" count with "Running on all eligible vulnerabilities" so the scope is unmistakable, and toggling it off (or switching actions) reverts to the manually selected rows.

In whole backlog mode, the two action components send an empty findingUuids array to the startVulnerabilityWorkflow mutation. The backend already treats an absent or empty array as "run on every finding in the project", so the client never enumerates ids. The success toast reports the scope rather than a count, since there is no count to report for a whole backlog run. The existing workflow progress bar continues to show the real "X of N processed" total once the run starts.

No new feature flag is introduced. The surface is already gated by the default off bulk_vulnerabilities_duo_workflow_api beta flag, so a nested flag would add a second dial without giving independent rollout control.

Screencast

How to set up and validate locally

  1. Enable the bulk_vulnerabilities_duo_workflow_api feature flag.
  2. Open a project with SAST vulnerabilities, with Duo available.
  3. Go to the project's Vulnerability Report.
  4. Select any vulnerability row and open the bulk action dropdown.
  5. Choose "Detect false positives" or "Resolve with AI" and confirm the "Select all eligible" toggle appears in the selection banner.
  6. Toggle it on and confirm the banner label switches to "Running on all eligible vulnerabilities".
  7. Toggle it off, or pick the other action, and confirm the banner reverts to the manually selected row count.
  8. Submit the action in whole backlog mode and confirm the toast reports the scope, and the progress bar shows real progress.

Known limitation

AppendBySeverityService applies no per action eligibility filter on the whole backlog path. It enqueues every Vulnerabilities::Finding in the project, including non SAST rows and ones already being analyzed. The "eligible" wording reflects the flow's intent, not an enforced backend filter. Scoping the backend relation by report type and active flag state is follow up work.

Screenshots are pending.

Closes #618536 (closed)

Edited by Savas Vedova

Merge request reports

Loading
Loading