Add support for git tags in Scan Execution Policies

Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.

Why are we doing this work

As requested:

The customer has flagged that the Scan Execution Policy doesn’t currently apply to Git tags, which some of their teams rely on for deployment. This limitation has significant compliance implications for their project and could pose a broader business risk by potentially delaying critical deployments or adding manual steps to meet their regulatory requirements. This is a high priority for the customer.

The idea for this issue is to add an additional option to Scan Execution Policies to be enforced on Git tags instead of branches, as it is not possible today.

image

Relevant links

Non-functional requirements

  • Documentation:
  • Feature flag:
  • Performance:
  • Testing:

Implementation plan

Verification steps

Edited by 🤖 GitLab Bot 🤖