Threat Insights priorities

Purpose

This issue is for high-level prioritization of groupthreat insights items. It primarily includes feature/product items and is not a comprehensive list of everything that will be worked such as bugs, implementation issues, documentation, or technical debt. It is not intended as a replacement or alternative for our issue boards. It is meant as an easily consumable single view of the main in-progress and upcoming work items for the Threat Insights group. It also allows mixing Epics and Issues in a single list.

This list is not a guarantee of timing or order of delivery. Rather, use this as a guide to see the tops items we are working on and will be in the near future. The list purposefully does not extend out many milestones into the future to maintain focus and not set a false sense of priority. If you don't see an issue or Epic you are interested in, please check the Vulnerability Management category vision Epic for a full list.

Priorities

Possible statuses:

  • Not started: no implementation issues should be scheduled. There is likely a Design issue in progress, and there may be issues in planning breakdown. We may have implementation issues if we're planning to start it soon.
  • Started: the scope of the epic should be locked-down, and we have implementation issues scheduled.
  • Complete: epic is code complete and is in production but may be behind a feature flag. The epic may contain open issues; in this case the issues may be moved to a new epic.

Complete items are removed from the table once the code is in production without a feature flag, and a release post, if applicable, has been merged. The epic is closed at this point.

priority name BE DRI FE DRI Status Comment
1 Integrate developer security training 2.0 @subashis @sming-gitlab Started
2 Enforce validation of security reports @Quintasan @dpisek Started
3 Deprecate and remove Vulnerabilities::Feedback @subashis N/A Started 1 BE for 3 Milestones.
4 Migrate Pipeline Security Tab to GraphQL @jschafer @dpisek Started Help wanted: 1 BE for <1 Milestone, 0 FE
5 Vulnerability Management DDL to replace raw JSON in the DB (raw_metadata) @jschafer N/A Started
6 Deprecate project_fingerprint @minac N/A Started Help wanted: 1 BE for 1 Milestone.
7 Vulnerability GraphQL resource to access a single vulnerability @jschafer @dpisek Not started Help wanted: 1 BE for <1 Milestone, 0 FE
8 Vulnerability bulk status updates (blocked by &5629 (closed)) @ghavenga @lorenzvanherwaarden Not started
9 Dismissal types / reasons (blocked by &5629 (closed)) @ghavenga @lorenzvanherwaarden Not started
10 Auto-resolve vulnerabilities when not found in subsequent scans (blocked by &5629 (closed)) @minac Not started
11 Allow filtering vulnerability dashboard by non-remediated activity Not started
12 Enhanced filtering and basic search of Vulnerability lists Not started
13 Audit users can access all Vulnerability Management features Not started
14 Display vulnerabilities by age in Security Dashboards @jschafer @svedova Not started
15 Include Additional Information in Security Dashboard Export @subashis Not started
16 Group-level Security Dashboard: Security scanner status widget Not started
17 Deprecate vulnerability REST APIs @subashis Not started
18 Prepare for JIRA custom domains @Quintasan Not started
19 Use report_type in vulnerability report's Too @minac TBD Not started
20 Vulnerability::IssueLink migration @Quintasan TBD Not started
21 Remove the Security::PipelineVulnerabilitiesFinder class TBD Not started Help wanted: 1 BE for <1 Milestone.
22 [Feature flag] Enable description of feature createVulnerabilityJiraIssueViaGraphql @dpisek Not started
23 Use merge base for security MR widget various; see sub-Epics Not started Help wanted: 1 BE for 1 Milestone.
24 Improve performance for Vulnerability Report TBD N/A Not started
25 Improve the performance of vulnerabilitySeveritiesCount TBD Not started Help wanted: 1 BE for 1 Milestone.
26 Only load MR security widget findings after clicking "Expand" TBD Not started Help wanted: 1 BE, 1 FE for <1 Milestone.
27 Limits for security reports artifact size TBD Not started
28 MR Security widget refactor TBD @svedova Started Help wanted: FE for 2 Milestones. May need BE
29 Improve on and add vulnerability/finding GraphQL endpoints to allow frontend to write better code for existing features TBD @dftian Not started Help wanted: BE for <2 Milestones.
Edited by Michał Zając