Serve the malware filter alongside a project filter

What does this MR do and why?

Serve the malware filter alongside a project filter

Any project_ids on the group dependency list routed the request to Sbom::DependenciesFinder, which has no malware support, so the filter was dropped and the full list came back with the Malware chip still active. The guard existed only because the Elasticsearch finder ignored project_ids.

aggregated_query? replaces using_new_query? where the question was whether rows are aggregated representatives paged by cursor, which is now also true of the Elasticsearch path under a project filter.

Also did some refactor.

References

Closes: #627417 (closed)

How to set up and validate locally

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Rushik Subba

Merge request reports

Loading
Loading