Loading
Enable license expression feature flags by default
What does this MR do and why?
Enables two EE feature flags by default:
-
sync_v3_license_expressions— PackageMetadata license sync uses the v3 SPDX expression format from PDS instead of v2. -
license_expression_checker— license approval policies useLicenseExpressionChecker(understands SPDX compound expressions likeMIT AND Apache-2.0) instead ofDeniedLicensesChecker. Type changed fromwiptobeta, sincewipflags cannot bedefault_enabled: true.
Rollout issue for license_expression_checker to follow.
References
- Sync V3 license expression ingestion (gitlab-org#22880 - closed) • Orin Naaman • 19.4
- [FF] `sync_v3_license_expressions` — roll out t... (#626708 - closed) • Orin Naaman • 19.4
- Add `LicenseExpressionChecker`: feature flag + ... (#600032 - closed) • Imam Hossain • 19.2
Screenshots or screen recordings
Not applicable — no UI change.
How to set up and validate locally
bundle exec rspec ee/spec/models/package_metadata/sync_configuration_spec.rb \
ee/spec/workers/package_metadata/licenses_sync_worker_spec.rb \
ee/spec/services/security/scan_result_policies/update_license_approvals_service_spec.rbMR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Orin Naaman