Add select all eligible for bulk AI vulnerability actions
What does this MR do and why?
Bulk AI actions in the Vulnerability Report ("Detect false positives" and "Resolve with AI") were limited to per row and current page selection. Running either flow across a whole project backlog meant paging through the report and checking every row by hand, even though the backend already supported whole project runs.
This MR adds a "Select all eligible" toggle to the selection banner. It only appears once one of the two bulk AI actions is chosen from the action dropdown, it is scoped to that action, and it does not select rows across pages. Toggling it on replaces the "N Selected" count with "Running on all eligible vulnerabilities" so the scope is unmistakable, and toggling it off (or switching actions) reverts to the manually selected rows.
In whole backlog mode, the two action components send an empty findingUuids
array to the startVulnerabilityWorkflow mutation. The backend already treats
an absent or empty array as "run on every finding in the project", so the client
never enumerates ids. The success toast reports the scope rather than a count,
since there is no count to report for a whole backlog run. The existing workflow
progress bar continues to show the real "X of N processed" total once the run
starts.
No new feature flag is introduced. The surface is already gated by the default
off bulk_vulnerabilities_duo_workflow_api beta flag, so a nested flag would add
a second dial without giving independent rollout control.
Screencast
How to set up and validate locally
- Enable the
bulk_vulnerabilities_duo_workflow_apifeature flag. - Open a project with SAST vulnerabilities, with Duo available.
- Go to the project's Vulnerability Report.
- Select any vulnerability row and open the bulk action dropdown.
- Choose "Detect false positives" or "Resolve with AI" and confirm the "Select all eligible" toggle appears in the selection banner.
- Toggle it on and confirm the banner label switches to "Running on all eligible vulnerabilities".
- Toggle it off, or pick the other action, and confirm the banner reverts to the manually selected row count.
- Submit the action in whole backlog mode and confirm the toast reports the scope, and the progress bar shows real progress.
Known limitation
AppendBySeverityService applies no per action eligibility filter on the whole
backlog path. It enqueues every Vulnerabilities::Finding in the project,
including non SAST rows and ones already being analyzed. The "eligible" wording
reflects the flow's intent, not an enforced backend filter. Scoping the backend
relation by report type and active flag state is follow up work.
Screenshots are pending.
Closes #618536 (closed)