Static Analysis allocation toward SaaS Reliability initiative - 14.3, 14.4

This is the groupstatic analysis specific issue for gitlab-com/Product#2881 (closed). The purpose is to provide a tracking and organization issue for surfacing the critical customer needs and opportunities to improve SaaS reliability for each group. Once collected, we can surface this back up to the main parent issue in a clear way.

Asks

See: gitlab-com/Product#2881 (closed)

  • @tmccaslin (PM): Understand and share what are the minimal-must-do features/capabilities we should deliver to meet customer ARR commitments from 14.2 through 14.6
  • @twoodham (EM): Understand and share What are the top most things you could advocate for to improve reliability of your areas. In addition to improving reliability, consider observability needs to detect and fix reliability issues when they do occur in SaaS

Assessment

Must-do Features/Capabilities

Top Areas to Improve Reliability

Engineering Allocation - working doc
  • Goal: Reduce total cost of ownership for SAST and Secret Detection on GitLab.com.
  • Justification: Reduce cost of resources required to maintain and operate 16 SAST and Secret Detection analyzers on GitLab.com as well as increase feature development efficiency and confidence in quality. Analyzers run 4M+ jobs per month, have target runtimes of 5mins or less, and are actively updated every month.
  • Supporting information: &6430

The plan

Over the next Next1-3 releases we intend to work through these issues in priority order kanban style.

Security

Reliability & Performance

Enable new analyzers to take over reporting for existing vulnerabilities

  • Remap vulnerabilities to retire deprecated analyzers.

License SAST, Secret Detection by its granular features

Tech Debt

Safety Nets

Edited by Taylor McCaslin