Ignore OWASP identifiers in vulnerability deduplication

What does this MR do and why?

Vulnerability deduplication skips "type identifiers" such as CWE and WASC when it compares findings, because they describe a whole class of vulnerabilities. OWASP identifiers are the same kind of grouping identifier, but they were still used, so unrelated findings that share an OWASP category at the same location could be treated as duplicates. This MR adds an owasp? check to Gitlab::Ci::Reports::Security::Identifier, includes it in type_identifier?, and updates the deduplication docs to match.

Closes #583945.

Screenshots or screen recordings

Not applicable — backend change.

How to set up and validate locally

  1. Run bundle exec rspec spec/lib/gitlab/ci/reports/security/identifier_spec.rb.
  2. Run bundle exec rspec spec/services/security/merge_reports_service_spec.rb.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

This contribution was prepared with the help of an AI assistant. I reviewed the changes and take responsibility for them.

Merge request reports

Loading
Loading