Add feature flag for merge request risk classification widget

What does this MR do and why?

The merge request risk classification widget is not finished yet. Right now, anyone with the risk classification flow enabled on their project can see it on the merge request page.

This MR adds a feature flag, show_duo_mr_risk_classification_widget, so we can control who sees the widget while we finish the work. The flag is off by default. When it is off, the widget does not show, even if the risk classification flow is available. When it is on for a user, that user sees the widget on merge requests that have a risk assessment.

This lets us test the widget with a small group of people before we release it to everyone.

The widget still needs the existing duo_mr_risk_classification flag and a risk assessment on the merge request. This MR does not change how the widget looks or what data it shows.

References

Screenshots or screen recordings

With show_duo_mr_risk_classification_widget OFF

Screenshot_2026-09-18_at_15.33.43

With show_duo_mr_risk_classification_widget ON

Screenshot_2026-09-18_at_15.34.09

How to set up and validate locally

The prerequisite steps come from the merge request that added the widget: !251381 (merged)

  1. Enable the existing flag in the Rails console:
    Feature.enable(:duo_mr_risk_classification)
  2. Use an Ultimate license. This license makes the ai_features licensed feature available to the project.
  3. Enable the risk_classification/v1 foundational flow for the root namespace. Go to the group's Duo settings at http://gdk.test:3000/groups/gitlab-duo/-/edit#js-gitlab-duo-settings. Turn the toggle on.
  4. Open a merge request that has a risk assessment record. No background worker writes these records yet. Create the record by hand with the risk_scenario.rb script from !251381 (merged). Run scenario 11. It creates a complete assessment with a rationale and 3 signals.
  5. Open the Overview tab of the merge request. The show_duo_mr_risk_classification_widget flag is off by default. The "Risk assessment" widget does not render, even though every prerequisite above is met.
  6. Turn the flag on for your user in the Rails console:
    Feature.enable(:show_duo_mr_risk_classification_widget, User.find_by_username('root'))
  7. Hard reload the merge request page. The "Risk assessment" widget now renders. It appears between the Sessions widget and the approvals widget, with the risk tier and confidence badges.
  8. Turn the flag off again in the Rails console:
    Feature.disable(:show_duo_mr_risk_classification_widget, User.find_by_username('root'))
  9. Hard reload the page again. The widget disappears.

Always hard reload the page after you change the flag. The page reads the flag value from gon. The server writes this value into the page HTML when it renders the page. A normal reload can serve a cached page with the old flag value.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Wanderson Policarpo

Merge request reports

Loading
Loading