Loading
Add report_artifacts support for foundational flows
Closes https://gitlab.com/gitlab-org/gitlab/-/work_items/624355
What does this MR do?
Threads report_artifacts from FoundationalFlow definitions through to WorkloadDefinition so CI jobs declare artifact reports (e.g. SAST).
This closes the gap for foundational flows — external agents already support report_artifacts via RunService, but foundational flows had no way to declare them.
Changes
| File | What |
|---|---|
attributes.rb |
New report_artifacts attribute (default {}) on FoundationalFlow |
execute_workflow_service.rb |
Pass report_artifacts for foundational flows (pipeline hooks, mentions) |
start_workflow_service.rb |
Wire report_artifacts → WorkloadDefinition#artifacts_reports with type guard + warning log |
start_workflow_service_spec.rb |
3 test cases (happy path, absent, malformed) |
How it works
A foundational flow definition declares:
report_artifacts: { "sast" => ["gl-sast-report.json"] }This gets threaded through ExecuteWorkflowService → StartWorkflowService → WorkloadDefinition#to_job_hash, which generates:
artifacts:
reports:
sast:
- gl-sast-report.jsonThe runner uploads the file and GitLab ingests the SAST findings.
E2E verified on GDK
- Created a dummy foundational flow with
report_artifacts - Triggered via pipeline hook
- Runner executed the workload, uploaded
gl-sast-report.json - GitLab parsed the SAST report and ingested findings
Artifact exist
Artifact loaded to security tab
Artifact populate the vulnerability report
Edited by Mher Tolpin


