Pipeline issues per stage after switching to Auto DevOps

Here are some issues quickly identified in a merge request pipeline after switching to using Auto DevOps in !1216 (merged).

Build

  1. Shouldn't this upload the build artifacts and make them available to browse and download? See before v. after.

Test

  1. The code_quality seems to frequently fail, is this expected? See branch and master.
  2. The test jobs failed once. Expected?
  3. Is it expected to upload container images for each merge requests? See container registry.
  4. The container_scanning job passed but the log shows some errors due to no space left. Same for the dependency_scanning job.
  5. When the container_scanning job completes what should require attention? Are these negligible severity warnings negligible? Same for the dependency_scanning job.
  6. The license_management is uploading a report, shouldn't this be available to browse and download?
  7. The sast job looks ok! Maybe also add a message saying that scanning passed without any warnings?

DAST

  1. The dast job included some XSS warnings. Should the job pass?

Production

  1. The production rollout failed for 10% and 25%. Why and does the passing 100% rollout means it's deployed on all pods?
Edited Sep 02, 2020 by 🤖 GitLab Bot 🤖
Assignee Loading
Time tracking Loading