Skip to content

Replace data source for CVS on sbom change

Zamir Martins requested to merge replace_data_source_for_cvs_on_sbom_change into master

What does this MR do and why?

Replace data source for CVS on sbom change. This feature is behind dependency_scanning_using_sbom_reports feature flag.

EE: true

Related issue: #464575 (closed)

edit: After the initial review it has been suggested that there should be some kind of optmization for the calls to ::Security::Ingestion::IngestCvsSliceService.execute. This change has been added as part of !162881 (b201e520)

MR acceptance checklist

Please evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Screenshots or screen recordings

CVS on SBOM changes

gl-sbom-pypi-setuptools.cdx.json

Screenshot_2024-08-22_at_20.32.46

How to set up and validate locally

Numbered steps to set up and validate the change are strongly suggested.

Edited by Zamir Martins

Merge request reports

Loading