Enable security_policies_malware_attribute by default

What does this MR do?

Enables the security_policies_malware_attribute feature flag by default, exposing the malware detection rule (is_malicious) in MR approval policies for Dependency Scanning and Container Scanning.

The flag was wip type, which cannot be default-enabled, so this promotes it to beta (which can) and sets default_enabled: true.

Already enabled on staging and production via ChatOps and validated end-to-end — see verification notes and the rollout request.

Closes #601968 (closed)

Rollout issue: #602575 (already closed/complete — flag is at 100% on gprd via project + group actor)

Relevant logs and/or screenshots

n/a — YAML-only change.

Merge request reports

Loading
Loading