Filter dependency bump events on the payload source_ref

What does this MR do and why?

  • Two event subscription conditions in ee/lib/gitlab/event_store/subscriptions/dependency_management_subscriptions.rb loaded the pipeline from the database just to read its branch name.
  • These conditions run when the event is published, inside the web request, so the lookups added queries on a hot path.
  • Ci::PipelineFinishedEvent now carries source_ref, added in the MR linked below, so the branch check reads the payload instead.
  • dependency_bump_mr_pipeline? now runs no queries at all.
  • dependency_bump_mr_failure? still loads the pipeline, but only after the payload checks pass, because the enable_dependency_bump_breaking_changes flag is scoped to a namespace and needs the project's root ancestor.
  • The Gitlab::QueryLimiting override is removed, which is the point of this change.
  • One behaviour change: a pipeline id that no longer exists is no longer filtered out when the event is published. The worker already returns early when the pipeline is missing.

References

How to set up and validate locally

  1. Turn on the flag in the rails console: Feature.enable(:enable_dependency_bump_breaking_changes_pipeline_tracking)

  2. Pick a merge request created by the dependency management service account whose source branch starts with dependency-management/. Use a slash; dependency-management-foo will not match.

  3. In the rails console, create a pipeline on that branch and fail it:

    project = Project.find_by_full_path('<group>/<project>')
    mr = project.merge_requests.find_by(iid: <iid>)
    sha = project.repository.commit(mr.source_branch).sha
    pipeline = project.all_pipelines.create!(ref: mr.source_branch, sha: sha, source: :push, status: 'pending', user: mr.author)
    pipeline.drop!
  4. Check that a workflow was created for the merge request:

    Ai::DuoWorkflows::Workflow.for_merge_request(mr).with_workflow_definition('resolve_dependency_bump/experimental').last
  5. Repeat on a branch that is not a dependency-management branch and confirm no workflow is created.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

🤖 Generated with Claude Code

Edited by Hitesh Raghuvanshi

Merge request reports

Loading
Loading