Document Business Logic Security Analyzer (BLSA)

What does this MR do and why?

For Technical Writer review. Documents business logic scanning (BLSA), which has no docs page yet.

  • New page doc/user/application_security/business_logic_scanning/_index.md: what the scan finds, prerequisites, the ways to start a scan (Duo Chat recommended for full scans), how to configure it, and where results show.
  • New "Business logic profile" section on the security configuration profiles page.
  • Points the Security Configuration card's Learn more link (lib/gitlab/security/features.rb) at the new page. It linked to the application security overview until now. The scan profile category link is added by the UI MR (!258537 (merged)), pointing straight at this page.

Depends on !257199 (merged). UI: !258537 (merged), stacked on this MR. Part of the BLSA split of !246889.

Merge order: after !257199 (merged) and !257196 (merged) (MR-4), and before the UI MR (!258537 (merged)), so the UI's help link has a page to point at. The page describes results in the MR security widget and vulnerability report, which need !257196 (merged) merged first. It also describes features from !257465 (merged) (MR-3c, merged: changed-files scoping, BL_SCAN_EFFORT, BL_TARGET_FILES).

How to verify

  • Read the rendered page and the new profile section.
  • Check the Security Configuration card's Learn more link opens the new page.
  • docs-lint jobs pass.

Backward compatibility / impact on existing flows

Docs only, plus one help link. The page is marked Experiment, behind bl_security_analyzer.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Meir Benayoun

Merge request reports

Loading
Loading