Show BLSA in security configuration and inventory
What does this MR do and why?
Problem: With !257199 (merged), attaching a Business Logic scan profile turns on BLSA for a project, but the UI doesn't show it. The scan profile pages skip the Business Logic preset (the frontend has no category for it), and the Security Inventory has no Business Logic entry.
- Scan profiles: adds the Business logic category (name,
BLlabel, help text, Learn more link to the business logic scanning page from !258562 (merged)), so the preset and saved profiles show in the profile list, group scanners overview, enable-scanners wizard and Inventory bulk table. - Trigger text: the Business Logic trigger card says what the scan really does: changed files in the merge request, after its head pipeline succeeds (stale and merge train pipelines are skipped). The generic "full repository" text is wrong for this scan.
- Security Inventory: adds a
BLentry to the tool coverage badges, bars and coverage card. !257199 (merged) pushesbl_security_analyzerto the page, so the entry stays hidden while the flag is off.
Depends on !258562 (merged) (docs), which depends on !257199 (merged) (backend). Merges last. Part of the BLSA split of !246889.
Before / after
With bl_security_analyzer off for the top-level group, nothing changes.
| Surface | Input | Before | After |
|---|---|---|---|
| Scan profile pages | Flag on | Business Logic preset skipped | "Business Logic (default)" with the BL label |
| Profile detail and details modal | BL profile, MR pipeline trigger | Not shown | "Scans merge request changes after the pipeline succeeds", scope "Changed files in the merge request" |
| Profile detail and details modal | Any other scan type | Generic trigger text | Unchanged |
| Security Inventory | Flag on | No BL entry | BL badge, bar and coverage-card option |
| Security Inventory | Flag off | No BL entry | No BL entry |
The Inventory BL status comes from pipeline scans, which !257196 (merged) (MR-4) records. Until MR-4 merges, and until a scan has run, it shows as not configured.
Screenshots or screen recordings
Captured in a GDK on this branch (after) and master (before). The Inventory BL badge stays Not enabled until a scan has run: only MR-4 (!257196 (merged)) writes that status.
How to set up and validate locally
- Check out this branch. Turn on
bl_security_analyzerfor a top-level group. - Open Secure > Security configuration > Profiles for a project. "Business Logic (default)" shows with the
BLlabel. Open its details: the trigger card shows the Business Logic text. - Apply the profile to the project. The Business Logic card shows as enabled.
- Open the group's Security inventory. Each project has a
BLbadge, and the coverage card lists "Business logic scanning". - Turn the flag off. None of the above shows, and the other scanners look the same as before.
Backward compatibility / impact on existing flows
| Change | Risk | Mitigation |
|---|---|---|
resolveTriggers(triggers, scanType) |
Could change other scan types' trigger text. | Overrides exist only for BUSINESS_LOGIC. Specs cover the generic path. |
Inventory components read visibleScannerGroups() |
Could drop other scanner columns. | Returns the same groups, minus BUSINESS_LOGIC only while the flag is off. |
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.








