Spike: Investigate deprecation of project.pipeline.securityReportFindings in favour of project.pipeline.vulnerabilities

Time-box: 1 day

The goals of this spike are:

  1. Document the purpose and benefits of the deprecation/migration. E.g.: Would it enable us to better share queries, data and UI components between the pipeline security report and the vulnerability details page?
  2. Capture the frontend changes that are needed to move from project.pipeline.securityReportFindings to project.pipeline.vulnerabilities

Steps:

  1. Document the differences and similarities between the Vulnerability and PipelineSecurityReportFinding types
  2. Document how they are currently used on the frontend (queries and UI)
  3. Update Deprecate project.pipeline.securityReportFindin... (#343475 - closed) accordingly, so that it's workflowready for development or workflowrefinement.

For more context see this discussion: #343475 (comment 1383529565)

Edited by Thiago Figueiró