Consider defaulting Operational Vulnerabilities to Activity:Still Detected

Why are we doing this work

Reported in https://gitlab.com/gitlab-com/sec-sub-department/section-sec-request-for-help/-/issues/434

Currently the vulnerabilities tab defaults to Activity: Still Detected while the operational tab defaults to Activity: All Activity . Is there any reason for this difference? Can we default operational vulnerabilities to Still Detected?

Development vulnerabilities tab

image.png

Operational tab

image.png

Relevant links

Non-functional requirements

  • Documentation:
  • Feature flag:
  • Performance:
  • Testing:

Implementation plan

Verification steps