Remove vulnerability_malware_detection feature flag
What
This merge request removes the vulnerability_malware_detection Beta feature flag as part of graduating Malicious Packages from Beta to GA. The flag is currently default_enabled: true in production. This change keeps the enabled code path and removes the flag definition and all disabled paths.
Why
The vulnerability_malware_detection flag has been enabled by default in production and gated the malware detection UI on the vulnerability report and vulnerability details pages — the malware badge, the malware filter token, and the malware-finding treatment of scoring rows (CVSS/EPSS/KEV) and the remediation/solution section. Since the flag is no longer needed and production already runs with these features enabled, we can simplify the codebase by removing the flag and its disabled-path logic.
Backend changes
- Delete the flag YAML definition at
config/feature_flags/beta/vulnerability_malware_detection.yml. - Remove the
vulnerability_malware_detection_feature_flag_enabled?helper methods from theProjectandGroupmodels. - Simplify
Vulnerabilities::MalwareDetection.malware_detection_enabled_for?to return true for anyProjectorGroup(the type check that remains after the flag removal). - Remove all
push_force_frontend_feature_flag(:vulnerability_malware_detection, ...)calls from:- Projects vulnerability report controller
- Projects vulnerabilities controller
- Groups vulnerabilities controller
- Update specs in the affected model, concern, serializer (
VulnerabilityEntity), GraphQL type (VulnerabilityType), and resolver to remove flag-off test contexts.
Frontend changes
The flag was pushed to the frontend in five files under ee/app/assets/javascripts/. All glFeatures.vulnerabilityMalwareDetection / glFeatures?.vulnerabilityMalwareDetection checks are removed so the feature is always on, matching current production:
- Remove the flag term from the malware filter token gate in the vulnerability report filtered search (the token now shows based on advanced vulnerability management alone).
- Remove the flag term from the malware badge
v-ifin the vulnerability list (the badge now shows whenever the finding is malware). - Remove the flag gate in
risk.vue, so the scoring rows (CVSS/EPSS/KEV) are hidden for malware findings — the always-on behaviour (previously only applied with the flag on). - Remove the flag gate in
remediation.vue, so the solution section is hidden for malware findings. - Update the risk Storybook story to drop the
glFeaturesprovide and the flag reference. - Update the four corresponding Jest specs to drop the flag-off test cases.
A note for reviewers
This change is authored from the Composition Analysis / Malicious Packages side but touches both group::vulnerability management backend and frontend. The Vulnerability Management team should review, particularly the frontend changes.
Testing
Backend specs pass locally (concern, serializer, and GraphQL type specs: 134 examples, 0 failures) and rubocop is clean. Frontend Jest specs and ESLint could not be validated in the local environment (Node/Yarn is out of sync with yarn.lock), so the frontend changes are verified by inspection and should be confirmed by CI.
Related
- Closes #629304 (closed)
- Part of &23613