Static Analysis allocation toward SaaS Reliability initiative - 14.3, 14.4
This is the groupstatic analysis specific issue for gitlab-com/Product#2881 (closed). The purpose is to provide a tracking and organization issue for surfacing the critical customer needs and opportunities to improve SaaS reliability for each group. Once collected, we can surface this back up to the main parent issue in a clear way.
Asks
See: gitlab-com/Product#2881 (closed)
-
@tmccaslin (PM): Understand and share what are the minimal-must-do features/capabilities we should deliver to meet customer ARR commitments from 14.2 through 14.6 -
@twoodham (EM): Understand and share What are the top most things you could advocate for to improve reliability of your areas. In addition to improving reliability, consider observability needs to detect and fix reliability issues when they do occur in SaaS
Assessment
Must-do Features/Capabilities
-
VET False Positive Reduction https://gitlab.com/groups/gitlab-org/-/epics/4504 https://gitlab.com/gitlab-org/gitlab/-/issues/336024#note_637812836 Progress:Started -
Duplicate Vulns - #336615 (closed) Progress:Started -
Remapping of Vulns - &6440 (closed), #299589 (closed) -
Rework ADDITIONAL_CA_CERTS #327438 (closed)
Top Areas to Improve Reliability
Engineering Allocation - working doc
- Goal: Reduce total cost of ownership for SAST and Secret Detection on GitLab.com.
- Justification: Reduce cost of resources required to maintain and operate 16 SAST and Secret Detection analyzers on GitLab.com as well as increase feature development efficiency and confidence in quality. Analyzers run 4M+ jobs per month, have target runtimes of 5mins or less, and are actively updated every month.
- Supporting information: &6430
The plan
Over the next Next1-3 releases we intend to work through these issues in priority order kanban style.
Security ✅
-
Restrict write access to Static Analysis Containers. https://gitlab.com/gitlab-org/gitlab/-/issues/336372 -
Triage and resolve any new vulnerabilities https://gitlab.com/groups/gitlab-org/security-products/analyzers/-/security/vulnerabilities/?activity=NO_ACTIVITY Progress:Started -
Need issues created for these, by analyzer.
-
-
Standardize on alpine (mobsf, security-code-scan, kubesec)blocked-
MobSF: https://gitlab.com/gitlab-org/gitlab/-/issues/301062blocked -
Security-code-scan: https://gitlab.com/gitlab-org/gitlab/-/issues/336795 -
Intentionally saying no to OSI images (federal) for now.
-
Reliability & Performance
-
Changing non-ultimate MR finding presentation to show only net findings, not added/fixed https://gitlab.com/gitlab-org/gitlab/-/issues/336719 -
Disable auto-resolving of Secret Detection findings introduced in Merge Requests #223248 (closed) -
Optimizations of SAST_EXCLUDED_PATHS- pre-filter -
Optimizations of SAST_EXCLUDED_PATHS- safer defaults (excludevendor, etc) -
Rework ADDITIONAL_CA_CERTS #218840 (closed) -
Improve Explore improving diff calculation https://gitlab.com/gitlab-org/gitlab/-/issues/336720 -
Move vulnerability UUID generation to the analyzers: #336725 (closed)
Enable new analyzers to take over reporting for existing vulnerabilities
-
Remap vulnerabilities to retire deprecated analyzers.
License SAST, Secret Detection by its granular features
Tech Debt
-
Moving downstream tests into the analyzers. #336821 (closed) -
Move inline SAST Analyzer testdata into files #267013 (closed)
Safety Nets
-
Automatic validation of JSON Security Reports #34654 (closed) -
Analyzer-level timeouts (alongside build timeouts) https://gitlab.com/gitlab-org/gitlab/-/issues/336721 -
Timeouts per tier (20min free, 40min premium, 60min ultimate, etc..) -
Think about Self hosted runners if this timeout applies?
-
-
Cap report size for SAST https://gitlab.com/gitlab-org/gitlab/-/issues/220397
Edited by Taylor McCaslin