Notify users about breaking changes for DAST 2.0

Breaking changes that need a release post

Completed? Details Implementation issue Release post MR
Remove the legacy ZAP format fields (@generated, @version, site and spider) from the DAST report #33915 (closed) gitlab-com/www-gitlab-com!71420 (merged)
Remove AUTH_URL environment variable config option #299919 (closed)
Remove AUTH_USERNAME environment variable config option #299919 (closed) gitlab-com/www-gitlab-com!71422 (merged)
Remove AUTH_PASSWORD environment variable config option #299919 (closed) gitlab-com/www-gitlab-com!71422 (merged)
Remove AUTH_USERNAME_FIELD environment variable config option #299919 (closed) gitlab-com/www-gitlab-com!71422 (merged)
Remove AUTH_PASSWORD_FIELD environment variable config option #299919 (closed) gitlab-com/www-gitlab-com!71422 (merged)
Remove AUTH_SUBMIT_FIELD environment variable config option #299919 (closed)
Remove AUTH_FIRST_SUBMIT_FIELD environment variable config option #299919 (closed)
Remove AUTH_AUTO environment variable config option #299919 (closed)
Remove DAST_REQUEST_HEADER environment variable config option #299919 (closed)
Rename DAST_AUTH_EXCLUDE_URLS to DAST_EXCLUDE_URLS #289959 (closed) gitlab-com/www-gitlab-com!71422 (merged)
Default DAST_SPIDER_START_AT_HOST to false #267403 (closed) gitlab-com/www-gitlab-com!71844 (merged)
Remove full scan domain validation #293595 (closed) gitlab-com/www-gitlab-com!71418 (merged)

Release post process

  1. Implement the change
  2. Add the change to the next milestone's release post
  3. Include in the release post an example of the error that users will see if they haven't updated their configuration after updating to DAST 2.0
Edited by Avielle Wolfe