VR: Update "learn more" to point to availability section & explain why VR is disabled on some CWEs

Overview

Feedback indicated that it was confusing when the Resolve feature wasn't available. We currently link to the top level feature docs and don't explain why this isn't available on all CWEs.

image

From Slack (internal):

I discovered recently that we have restricted "Resolve with AI" to a subset of known CWE. While we don't have this restriction on "Explain with AI" and... we suggest a fix in the explanation.
Maybe I just missed the explanation so if you could direct me to it? This behaviour is confusing and users don't understand why "Resolve with AI" is now limited.

and from a customer (originally shared in Slack (internal)):

  1. They tried it on an old vulnerability two weeks ago and got an error that the feature was unable to provide a response. They were unsure of why that was the case and they were unable to locate that same vulnerability record.
  2. They tried it again today live on the call for 2 CWEs that the feature should have been available for. After the call Ron quickly determined that the root cause was because those identifiers were missing from the high-confidence list on the backend - we are adding them now
  3. [Customer] said it was unclear why the feature was disabled for a particular vulnerability - clicking on the Learn More button took him to the documentation but it was hard to find the section that clearly described why the feature is disabled.

Proposal

UI:

  • Update the Learn more link to point to the availability section at https://docs.gitlab.com/ee/user/application_security/vulnerabilities/#availability.

Docs:

  • Remove extra line break in docs.
  • Explain why some CWEs have VR disabled.
Edited Aug 20, 2024 by Becka Lippert
Assignee Loading
Time tracking Loading