Skip to content
GitLab
Next
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 44,761
    • Issues 44,761
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 1,332
    • Merge requests 1,332
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.orgGitLab.org
  • GitLabGitLab
  • Issues
  • #348655
Closed
Open
Issue created Dec 16, 2021 by Nicole Schwartz@NicoleSchwartzContributor0 of 6 checklist items completed0/6 checklist items

Design & Spike - associate Dependency and Container Scanning results to reduce duplicates and noise

Release notes

Problem to solve

As a user I want to know if my application is secure and so I run security scans. When the results come back i want to quickly understand and be able to action them. I don't want to waste my time, and duplicate findings waste my time.

Currently, DS finds some container dependencies, not all, CS finds more container dependencies - but we don't currently de-duplicate across different categories, this creates some duplicates and noise. As a result we don't have CS_DISABLE_LANGUAGE_VULNERABILITY_SCAN on by default - but we should figure out how to handle this best, and then it can be on by default to enable the most comprehensive coverage we can.

we do NOT want to de-duplicate but we want to group

https://about.gitlab.com/handbook/engineering/development/sec/secure/glossary-of-terms/

there may be many ways to accomplish this, evaluate and test one

one - group #267588 two - 1:many or many:many linking

Intended users

Metrics

User experience goal

Proposal

Further details

Permissions and Security

Documentation

Availability & Testing

Available Tier

What does success look like, and how can we measure that?

What is the type of buyer?

Is this a cross-stage feature?

Links / references

Edited Apr 22, 2022 by Nicole Schwartz
Assignee
Assign to
Time tracking