Telemetry - add the ability to tie rule type to analyzer version
Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.
Problem to solve
Today in groupsecret detection we don't know what rules are causing the most false positives. Inaccurate secret detection patterns can create unnecessary noise for security teams. We need to minimize false positives (FPs) so true positives (TPs) can be triaged and remediated quickly. We need to better understand what rules create the most false positives (FPs) AND be able to correlate analyzer versions to new noise.
Proposal
Create a way to tie analyzer versions to our default rulesets for pipeline secret detection.
Edited by 🤖 GitLab Bot 🤖