Display Vulnerability count consistently on the Pipeline and Dashboard views

Problem to solve

Display Vulnerability count consistently on the Pipeline and Dashboard views and some UI improvements.

Intended users

  • Security Analyst
  • Development Team Lead

Further details

As a security analyst, I like to see the Project security dashboard and get a total count on the vulnerabilities on the project so that I can track the progress of the development team. But when I go to the pipeline security view to contribute my understanding of the issues, the counts do not look correct, and the information is organized much differently.

As a Development Team Lead, I do not have a clear and concise way of identifying one problem at a time for my team to fix prior to merging a branch. On the pipeline security view, the vulnerabilities are concatenated into types of vulnerabilities. However, the Security Dashboard (which I also like to view from time to time have each finding listed as a separate vulnerability which gives the security team a different picture than what I get for my team.

Proposal

  1. The count of vulnerabilities displayed in the pipeline security view should reflect exact count of all the found vulnerabilities.
  2. The list of vulnerabilities in each category displayed in the pipeline security view should have a clear indicator that there are more with an appropriate scroll bar, so the user knows to scroll down further.
  3. Counts in the pipeline security view should probably match the security dashboard at least for the master.

Permissions and Security

  • Developer
  • Maintainer

Documentation

Testing

What does success look like, and how can we measure that?

Numbers should match, or there should be a clear explanation of why they do not in the Pipeline Security view and the Security dashboard

What is the type of buyer?

EE Ultimate user

Links / references

Assignee Loading
Time tracking Loading