Loading
Register business_logic as a platform analyzer type
What does this MR do and why?
Registers business_logic as a platform analyzer type for the Business Logic Security Analyzer (BLSA).
- No scan runs because of this MR. It only makes the type known to the platform.
- Customer-visible parts are behind a new flag,
bl_security_analyzer(experiment, off by default). - Enablement is profile-only, like
triage_and_remediation. There is no per-project toggle. !257199 (merged) adds the default scan profile.
First MR of the BLSA split of !246889. Tracker: https://gitlab.com/gitlab-org/gitlab/-/work_items/630266.
What changes for users
| Surface | Flag off | Flag on |
|---|---|---|
| Security Configuration page | No Business Logic card | Business Logic card shown |
securityScanProfileCreate with BUSINESS_LOGIC |
Rejected (same error as triage_and_remediation) |
Passes the flag check, then fails validation: no trigger types are allowed yet |
securityScanners.available |
No BUSINESS_LOGIC |
Lists BUSINESS_LOGIC |
| Six GraphQL enums (list below) | BUSINESS_LOGIC present |
Same |
group.analyzerStatuses, inventory filter |
Accept or return BUSINESS_LOGIC |
Same |
- The flag actor is the top-level namespace everywhere.
- The ungated enum values are harmless: the frontend uses hard-coded analyzer lists, so nothing renders them.
- Enums:
AnalyzerTypeEnum,AnalyzerTypeForStatus,LicensedFeature,SecurityReportTypeEnum,SecurityScanProfileType,SecurityScannerType.
Review focus
- Database: one column,
security_inventory_filters.business_logic. It must ship here becauseSecurity::InventoryFilterbuilds an enum per analyzer type. Without it, every project factory fails. - Security / platform: the three flag gates, and the Ultimate entry in
GitlabSubscriptions::Features.
Design decisions
- Introspection JSON: the enum values were inserted by script, not regenerated. The diff adds only those values.
Not in this MR (later in the stack)
- Merge order: !257092 (merged) (AI Catalog flow) uses this flag, so it merges after this MR.
- Help link: the card links to the application security overview until the docs page lands in !257199 (merged).
Known limitations
- Expected conflict: a trivial
db/structure.sqlconflict with !256967 (merged) (same table, no enum overlap).
Files in this MR
- Enums:
app/models/concerns/enums/security.rb - Ultimate entry:
ee/app/models/gitlab_subscriptions/features.rb - Analyzer registry:
lib/gitlab/security/features.rb - Flag:
config/feature_flags/experiment/bl_security_analyzer.yml(ownergroup::code security) - Migration:
db/migrate/20260923170038_add_business_logic_to_security_inventory_filters.rb+db/structure.sql - Generated: GraphQL reference, introspection JSON, 3 strings in
locale/gitlab.pot - Specs: flag gates (presenter, mutation,
available_scanners), root-namespace actor, enum and feature tables
Changes relative to the source branch
Ported from bl-security-analyzer (!246889), limited to business_logic registration.
- Added the flag gates and moved the flag definition here.
- Dropped the per-project toggle and everything that existed only for it.
- Flag owner set to
group::code security; migration milestone19.5(was19.3). business_logicmoved to its alphabetical place inULTIMATE_FEATURES.
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, and security.
- I have self-reviewed this MR per code review guidelines
Edited by Meir Benayoun