Enable license expression feature flags by default

What does this MR do and why?

Enables two EE feature flags by default:

  • sync_v3_license_expressions — PackageMetadata license sync uses the v3 SPDX expression format from PDS instead of v2.

  • license_expression_checker — license approval policies use LicenseExpressionChecker (understands SPDX compound expressions like MIT AND Apache-2.0) instead of DeniedLicensesChecker. Type changed from wip to beta, since wip flags cannot be default_enabled: true.

Rollout issue for license_expression_checker to follow.

References

Screenshots or screen recordings

Not applicable — no UI change.

How to set up and validate locally

bundle exec rspec ee/spec/models/package_metadata/sync_configuration_spec.rb \
  ee/spec/workers/package_metadata/licenses_sync_worker_spec.rb \
  ee/spec/services/security/scan_result_policies/update_license_approvals_service_spec.rb

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Orin Naaman

Merge request reports

Loading
Loading