Remove vulnerability_malware_detection feature flag

What

This merge request removes the vulnerability_malware_detection Beta feature flag as part of graduating Malicious Packages from Beta to GA. The flag is currently default_enabled: true in production. This change keeps the enabled code path and removes the flag definition and all disabled paths.

Why

The vulnerability_malware_detection flag has been enabled by default in production and gated the malware detection UI on the vulnerability report and vulnerability details pages — the malware badge, the malware filter token, and the malware-finding treatment of scoring rows (CVSS/EPSS/KEV) and the remediation/solution section. Since the flag is no longer needed and production already runs with these features enabled, we can simplify the codebase by removing the flag and its disabled-path logic.

Backend changes

  • Delete the flag YAML definition at config/feature_flags/beta/vulnerability_malware_detection.yml.
  • Remove the vulnerability_malware_detection_feature_flag_enabled? helper methods from the Project and Group models.
  • Simplify Vulnerabilities::MalwareDetection.malware_detection_enabled_for? to return true for any Project or Group (the type check that remains after the flag removal).
  • Remove all push_force_frontend_feature_flag(:vulnerability_malware_detection, ...) calls from:
    • Projects vulnerability report controller
    • Projects vulnerabilities controller
    • Groups vulnerabilities controller
  • Update specs in the affected model, concern, serializer (VulnerabilityEntity), GraphQL type (VulnerabilityType), and resolver to remove flag-off test contexts.

Frontend changes

The flag was pushed to the frontend in five files under ee/app/assets/javascripts/. All glFeatures.vulnerabilityMalwareDetection / glFeatures?.vulnerabilityMalwareDetection checks are removed so the feature is always on, matching current production:

  • Remove the flag term from the malware filter token gate in the vulnerability report filtered search (the token now shows based on advanced vulnerability management alone).
  • Remove the flag term from the malware badge v-if in the vulnerability list (the badge now shows whenever the finding is malware).
  • Remove the flag gate in risk.vue, so the scoring rows (CVSS/EPSS/KEV) are hidden for malware findings — the always-on behaviour (previously only applied with the flag on).
  • Remove the flag gate in remediation.vue, so the solution section is hidden for malware findings.
  • Update the risk Storybook story to drop the glFeatures provide and the flag reference.
  • Update the four corresponding Jest specs to drop the flag-off test cases.

A note for reviewers

This change is authored from the Composition Analysis / Malicious Packages side but touches both group::vulnerability management backend and frontend. The Vulnerability Management team should review, particularly the frontend changes.

Testing

Backend specs pass locally (concern, serializer, and GraphQL type specs: 134 examples, 0 failures) and rubocop is clean. Frontend Jest specs and ESLint could not be validated in the local environment (Node/Yarn is out of sync with yarn.lock), so the frontend changes are verified by inspection and should be confirmed by CI.

Merge request reports

Loading
Loading