Register business_logic as a platform analyzer type

What does this MR do and why?

Registers business_logic as a platform analyzer type for the Business Logic Security Analyzer (BLSA).

  • No scan runs because of this MR. It only makes the type known to the platform.
  • Customer-visible parts are behind a new flag, bl_security_analyzer (experiment, off by default).
  • Enablement is profile-only, like triage_and_remediation. There is no per-project toggle. !257199 (merged) adds the default scan profile.

First MR of the BLSA split of !246889. Tracker: https://gitlab.com/gitlab-org/gitlab/-/work_items/630266.

What changes for users

Surface Flag off Flag on
Security Configuration page No Business Logic card Business Logic card shown
securityScanProfileCreate with BUSINESS_LOGIC Rejected (same error as triage_and_remediation) Passes the flag check, then fails validation: no trigger types are allowed yet
securityScanners.available No BUSINESS_LOGIC Lists BUSINESS_LOGIC
Six GraphQL enums (list below) BUSINESS_LOGIC present Same
group.analyzerStatuses, inventory filter Accept or return BUSINESS_LOGIC Same
  • The flag actor is the top-level namespace everywhere.
  • The ungated enum values are harmless: the frontend uses hard-coded analyzer lists, so nothing renders them.
  • Enums: AnalyzerTypeEnum, AnalyzerTypeForStatus, LicensedFeature, SecurityReportTypeEnum, SecurityScanProfileType, SecurityScannerType.

Review focus

  • Database: one column, security_inventory_filters.business_logic. It must ship here because Security::InventoryFilter builds an enum per analyzer type. Without it, every project factory fails.
  • Security / platform: the three flag gates, and the Ultimate entry in GitlabSubscriptions::Features.

Design decisions

  • Introspection JSON: the enum values were inserted by script, not regenerated. The diff adds only those values.

Not in this MR (later in the stack)

  • Merge order: !257092 (merged) (AI Catalog flow) uses this flag, so it merges after this MR.
  • Help link: the card links to the application security overview until the docs page lands in !257199 (merged).

Known limitations

  • Expected conflict: a trivial db/structure.sql conflict with !256967 (merged) (same table, no enum overlap).
Files in this MR
  • Enums: app/models/concerns/enums/security.rb
  • Ultimate entry: ee/app/models/gitlab_subscriptions/features.rb
  • Analyzer registry: lib/gitlab/security/features.rb
  • Flag: config/feature_flags/experiment/bl_security_analyzer.yml (owner group::code security)
  • Migration: db/migrate/20260923170038_add_business_logic_to_security_inventory_filters.rb + db/structure.sql
  • Generated: GraphQL reference, introspection JSON, 3 strings in locale/gitlab.pot
  • Specs: flag gates (presenter, mutation, available_scanners), root-namespace actor, enum and feature tables
Changes relative to the source branch

Ported from bl-security-analyzer (!246889), limited to business_logic registration.

  • Added the flag gates and moved the flag definition here.
  • Dropped the per-project toggle and everything that existed only for it.
  • Flag owner set to group::code security; migration milestone 19.5 (was 19.3).
  • business_logic moved to its alphabetical place in ULTIMATE_FEATURES.

MR acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, and security.

Edited by Meir Benayoun

Merge request reports

Loading
Loading