Show BLSA in security configuration and inventory

What does this MR do and why?

Problem: With !257199 (merged), attaching a Business Logic scan profile turns on BLSA for a project, but the UI doesn't show it. The scan profile pages skip the Business Logic preset (the frontend has no category for it), and the Security Inventory has no Business Logic entry.

  • Scan profiles: adds the Business logic category (name, BL label, help text, Learn more link to the business logic scanning page from !258562 (merged)), so the preset and saved profiles show in the profile list, group scanners overview, enable-scanners wizard and Inventory bulk table.
  • Trigger text: the Business Logic trigger card says what the scan really does: changed files in the merge request, after its head pipeline succeeds (stale and merge train pipelines are skipped). The generic "full repository" text is wrong for this scan.
  • Security Inventory: adds a BL entry to the tool coverage badges, bars and coverage card. !257199 (merged) pushes bl_security_analyzer to the page, so the entry stays hidden while the flag is off.

Depends on !258562 (merged) (docs), which depends on !257199 (merged) (backend). Merges last. Part of the BLSA split of !246889.

Before / after

With bl_security_analyzer off for the top-level group, nothing changes.

Surface Input Before After
Scan profile pages Flag on Business Logic preset skipped "Business Logic (default)" with the BL label
Profile detail and details modal BL profile, MR pipeline trigger Not shown "Scans merge request changes after the pipeline succeeds", scope "Changed files in the merge request"
Profile detail and details modal Any other scan type Generic trigger text Unchanged
Security Inventory Flag on No BL entry BL badge, bar and coverage-card option
Security Inventory Flag off No BL entry No BL entry

The Inventory BL status comes from pipeline scans, which !257196 (merged) (MR-4) records. Until MR-4 merges, and until a scan has run, it shows as not configured.

Screenshots or screen recordings

Surface Before After
Security Configuration card status (BL profile attached) 1-config-before 1-config-after
Security Inventory BL badge 2-inventory-before 2-inventory-after
Scan profile list and details modal trigger text 1b-config-profiles-before 3b-profile-modal-after
Group Enable scanners wizard, coverage column 4-wizard-coverage-before 4-wizard-coverage-after
Flag off: no Business Logic row or card 1b-config-profiles-before 5-flag-off

Captured in a GDK on this branch (after) and master (before). The Inventory BL badge stays Not enabled until a scan has run: only MR-4 (!257196 (merged)) writes that status.

How to set up and validate locally

  1. Check out this branch. Turn on bl_security_analyzer for a top-level group.
  2. Open Secure > Security configuration > Profiles for a project. "Business Logic (default)" shows with the BL label. Open its details: the trigger card shows the Business Logic text.
  3. Apply the profile to the project. The Business Logic card shows as enabled.
  4. Open the group's Security inventory. Each project has a BL badge, and the coverage card lists "Business logic scanning".
  5. Turn the flag off. None of the above shows, and the other scanners look the same as before.

Backward compatibility / impact on existing flows

Change Risk Mitigation
resolveTriggers(triggers, scanType) Could change other scan types' trigger text. Overrides exist only for BUSINESS_LOGIC. Specs cover the generic path.
Inventory components read visibleScannerGroups() Could drop other scanner columns. Returns the same groups, minus BUSINESS_LOGIC only while the flag is off.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Meir Benayoun

Merge request reports

Loading
Loading