Add report_artifacts support for foundational flows

Closes https://gitlab.com/gitlab-org/gitlab/-/work_items/624355

What does this MR do?

Threads report_artifacts from FoundationalFlow definitions through to WorkloadDefinition so CI jobs declare artifact reports (e.g. SAST).

This closes the gap for foundational flows — external agents already support report_artifacts via RunService, but foundational flows had no way to declare them.

Changes

File What
attributes.rb New report_artifacts attribute (default {}) on FoundationalFlow
execute_workflow_service.rb Pass report_artifacts for foundational flows (pipeline hooks, mentions)
start_workflow_service.rb Wire report_artifacts → WorkloadDefinition#artifacts_reports with type guard + warning log
start_workflow_service_spec.rb 3 test cases (happy path, absent, malformed)

How it works

A foundational flow definition declares:

report_artifacts: { "sast" => ["gl-sast-report.json"] }

This gets threaded through ExecuteWorkflowService → StartWorkflowService → WorkloadDefinition#to_job_hash, which generates:

artifacts:
  reports:
    sast:
    - gl-sast-report.json

The runner uploads the file and GitLab ingests the SAST findings.

E2E verified on GDK

  • Created a dummy foundational flow with report_artifacts
  • Triggered via pipeline hook
  • Runner executed the workload, uploaded gl-sast-report.json
  • GitLab parsed the SAST report and ingested findings

Artifact exist

image

Artifact loaded to security tab

image

Artifact populate the vulnerability report

image

Edited by Mher Tolpin

Merge request reports

Loading
Loading