Show per-signal risk impact and label claim domains

What does this MR do and why?

Makes the merge request risk classification widget easier to interpret. Each signal in the breakdown now shows whether it raised or lowered the risk score, and claim rows display human-readable labels instead of raw keys.

frontend The widget now fetches contribution from GraphQL and renders a directional tag per row -- red for risk-raising, green for risk-lowering, gray for no change -- with text weight (Major/plain/Minor) conveying size. The low-confidence notice is moved out of the score breakdown into its own "What lowered confidence" section, so confidence and score are no longer mixed together.

backend SignalsExtractor.label_for now falls back to each claim's translated domain description, so credentials_crypto renders as "Cryptography, key management, or credential handling" instead of a raw key. The scoring function also drops rows that round to zero contribution, and the internal mitigation_cap row is hidden from the UI.

References

Screenshots or screen recordings

Score with high confidence

Before After
CleanShot_2026-09-28_at_8.54.25_PM_2x CleanShot_2026-09-28_at_8.26.07_PM_2x

Score with low confidence

Before After
CleanShot_2026-09-28_at_8.58.55_PM_2x CleanShot_2026-09-28_at_8.26.43_PM_2x

How to set up and validate locally

  1. Enable the feature flags in the Rails console:
    Feature.enable(:show_duo_mr_risk_classification_widget)
    Feature.enable(:duo_mr_risk_classification)
  2. Open a merge request that has a completed risk assessment with a low confidence tier and a mix of contributing/missing signals.
  3. Expand the Risk assessment widget and confirm:
    • each row under What affected the risk score shows a directional impact tag (Major/Minor increase/decrease, or no change), with color only on the icon;
    • no raw point numbers or a mitigation_cap row appear;
    • claim rows show human‑readable names (e.g. "Cryptography, key management, or credential handling") rather than raw keys;
    • a What lowered confidence section renders after the breakdown, listing each unmeasured input on its own line.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Austin Regnery

Merge request reports

Loading
Loading