Allow notes when dismissing vulnerabilities from Security Dashboard

Release notes

Currently when dismissing a vulnerability any rationale needs to be documented outside of the security dashboard - this could be in the Gitlab wiki, Google docs, etc. Keeping all compliance related information within the Security Dashboard has immense value.

Problem to solve

Allow users to expound upon rationale for dismissing a detected vulnerability as fixed. This should allow for the developer or security officer to tie a dismissal to a commit/MR and provide notes for why it was dismissed.

Intended users

User experience goal

Reduce the stress of a user dismissing a found vulnerability. Some are easy, as they are clearly classified as unfounded, but others require a bit of explanation. Without context, the dismissal feels like sweeping something under the rug.

Proposal

Allow a user to enter notes to the found vulnerability on why it was dismissed.

Further details

Permissions and Security

Documentation

Availability & Testing

What does success look like, and how can we measure that?

What is the type of buyer?

Is this a cross-stage feature?

Links / references