Reserve profile name for default profiles
What does this MR do and why?
Adds a name_not_reserved validation to Security::ScanProfile that rejects any custom profile whose name matches a GitLab-recommended default profile name.
Default profiles are materialized lazily by Security::ScanProfiles::FindOrCreateService, which upserts on the (namespace_id, scan_type, lower(name)) partial unique index. Custom profile squatting a default name was silently converted into the recommended profile on the next attach, overwriting its name and description, flipping gitlab_recommended to true, and merging the default triggers into it. Once flipped, the profile could no longer be edited or deleted by its owner. Reserving the four default names at the model layer closes both the create and rename paths.
The validation runs only when name changes and is skipped for gitlab_recommended profiles, so the service's own upsert and any pre-existing rows are unaffected.
Changelog: fixed
EE: true
How to set up and validate locally
-
Confirm the reserved names:
Security::DefaultScanProfilesHelper.default_scan_profiles.map(&:name) # => ["Secret Detection (default)", "SAST (default)", "Dependency Scanning (default)", # "Dependency Scanning Auto-Remediation (default)"] -
Creating a custom profile with a reserved name is rejected:
mutation { securityScanProfileCreate(input: { namespaceId: "gid://gitlab/Group/<ROOT_GROUP_ID>" scanType: SAST name: "SAST (default)" description: "test" triggers: [{ triggerType: DEFAULT_BRANCH_PIPELINE }] }) { errors scanProfile { id name } } }Returns
errors: ["Name is reserved for GitLab-recommended scan profiles."]andscanProfile: null. -
Renaming an existing custom profile to a reserved name is rejected the same way:
mutation { securityScanProfileUpdate(input: { id: "gid://gitlab/Security::ScanProfile/<PROFILE_ID>" name: "SAST (default)" }) { errors scanProfile { name } } }The profile keeps its previous name.
-
Run the specs:
bundle exec rspec ee/spec/models/security/scan_profile_spec.rb \ ee/spec/lib/security/default_scan_profiles_spec.rb \ ee/spec/requests/api/graphql/mutations/security/scan_profiles/create_spec.rb \ ee/spec/requests/api/graphql/mutations/security/scan_profiles/update_spec.rb
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.