15.3 Planning for Compliance
This issue and linked pages contain information related to upcoming products, features, and functionality. It is important to note that the information presented is for informational purposes only. Please do not rely on this information for purchasing or planning purposes. As with all projects, the items mentioned in this video and linked pages are subject to change or delay. The development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.
Once moved out of draft, update the kickoff issue
Table of Contents
- Boards
- Capacity notes
- Objectives & Themes
- Release Post Items
Boards
Different boards we use for planning and organization
- Build Board (%14.9 milestone issues to be built)
- Next Up Board (all Next Up issues with workflow states)
- Milestone scheduling board
- Maintenance board
- Refinement Queue (stack rank of issues to refine in order)
- Bug Board (bugs organized by severity labels)
- UX Board
- Audit Event Organization
- Error budgets - Grafana/Sisense
Capacity notes
- Milestone runs from 2022-07-22 to 2022-08-22
Capacity by team member
- Rob - 6w
- Huzaifa - 2w
- Max - 9w
- Harsimar - 7w
- Jiaan - 4w
- Michael - 4w
Objectives & Themes
Product prioritized typefeature list
- Any %15.2 carry-over
-
https://gitlab.com/groups/gitlab-org/-/epics/7611+
- Consider the tasks active in this coverage issue
- Specific event shortlist to add event type info... (gitlab-org&8118 - closed)
- Add event type information for all streaming au... (gitlab-org&8057 - closed)
- UI screens to specify custom HTTP headers for s... (gitlab-org&7975 - closed)
- Optimize compliance violations query (gitlab-org/gitlab#363357 - closed)
- Handle missing gitlab-ci.yml files using compli... (gitlab-org/gitlab#364131 - closed)
-
🔍 New Audit Event: Custom HTTP headers changed fo... (gitlab-org/gitlab#366350 - closed)
-
https://gitlab.com/groups/gitlab-org/-/epics/7611+
- New feature work
- MVP filter violations by all branches or all pr... (gitlab-org&7916 - closed)
-
2️⃣ Allow user to specify verificationToken value a... (gitlab-org/gitlab#360813 - closed) -
3️⃣ Generate chain of custody CSV reports asyncrono... (gitlab-org/gitlab#342594 - closed) -
2️⃣ [Chain of Custody Report] Expand the scope from... (gitlab-org/gitlab#267601 - closed)
Engineering prioritized typemaintenance list
- Any %15.2 carry-over
- New maintenance work.
* This is a nominal weight to represent groupcompliance's assistance in refining the pattern for code owners.
Quality prioritized typebug list
| LINKED_ISSUE_TITLE | BUG_AGE | SEVERITY_TAG | PRIORITY_TAG | MILESTONE_TITLE |
|---|---|---|---|---|
| Content injection via `Status checks` widget in... (gitlab-org/gitlab#367408 - closed) | sev 2 | prio 2 | ||
| Sometimes the chain of custody report returns an empty CSV | 7 | severity 2 | priority 2 | |
| Group Level Audit Logging shows incorrect IP address when SAML a | 638 | severity 3 | priority 2 | |
Compliance pipelines do not expand .extends blocks before incl |
335 | severity 3 | priority 2 | |
| Filter bar missing for developers in audit events | 244 | severity 3 | priority 2 | |
| audit_json.log does not contain all audit events | 43 | severity 3 | priority 2 | |
| Compliance report does not always show properly... (gitlab-org/gitlab#367675 - closed) | 1 | severity 3 | priority 2 | |
| Missing group audit log when project is added to existing group | 1031 | severity 3 | undefined | Backlog |
Deferred Items
Deferred items from previous and the current milestone
Consider moving to following iteration and/or moving to workflow::scheduling