Loading
Fix triage and remediation profile defaults
What does this MR do and why?
Corrects the Triage and Remediation :icecream presets so their values match the updated product definition.
The presets (Conservative, Standard, Proactive) already exist on master, but the table that defines them was revised after they were merged:
| Correction | Detail |
|---|---|
| SAST VR merge request limit | New open_merge_requests_limit on the SAST vulnerability resolution JSON schema. Preset values 5 / 15 / null, where null means no limit. |
| Vulnerability enrichment severity | New severity_level on the vulnerability enrichment JSON schema. Preset values high / medium / info. The three presets previously carried identical configuration for this trigger. |
| Dependency baseline realigned | Standard's sbom_ingested now references DependencyScanningPostProcessing::VALUES directly rather than restating it, so the Triage and Remediation baseline cannot drift from the existing dependency defaults again. Restores severity high and runner_tags. |
Changelog: fixed
EE: true
Related issue
[Backend] Add Conservative / Standard / Proacti... (#622469 - closed) • Gal Katz • 19.4
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.