Skip to content

Dont run SAST on tests

Dennis Appelt requested to merge da/ignore-tests-in-security-reports into master

What does this MR do?

Don't run SAST on test folders /qa, /doc and /specs. This will help to declutter the finding lists in the security dashboard.

Does this MR meet the acceptance criteria?

Conformity

Performance and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Dennis Appelt

Merge request reports