Notice: Removal of End-of-Support SAST analyzer jobs
Deprecation Summary
Add a brief description of the feature or functionality that is deprecated. Clearly state the potential impact of the deprecation to end users.
Actions Required
You only need to take action if:
- You applied customizations to one of the affected analyzers, such as setting a variable like
SAST_EXCLUDED_ANALYZERSspecifically on a job likeeslint-sast, and that customization still applies to Semgrep.- You should migrate any option that is still needed to the
semgrep-sastjob. - Note that the
semgrep-sastjob itself handles multiple languages. Some of your previous customizations, especially those related to build or compilation processes, may no longer be neccessary or may not apply to all languages covered by the Semgrep analyzer.
- You should migrate any option that is still needed to the
- You customized a built-in rule from one of the affected analyzers and still need the customization in Semgrep.
- You should update the customization to refer to the rule's new identifier in this case.
- You have explicitly disabled the Semgrep-based analyzer.
- You should re-enable the Semgrep-based analyzer in this case.
- You use the GitLab-managed CI/CD template and your pipeline configuration explicitly depends on a job name like
bandit-sastorspotbugs-sast.- You should change your pipeline to refer to
semgrep-sastor otherwise update it, depending on your use case.
- You should change your pipeline to refer to
Documentation
- Deprecation notice: Announce removal of End-of-Support SAST CI jobs (!179946 - merged)
- Migration guidelines: pending
Product Usage
Describe why deprecation of this feature is necessary, ideally with dashboards/metrics that show product usage. add links to the documentation
Breaking Change?
Does this deprecation contain a breaking change? Yes, albeit in limited cases
Affected Customers
Who is affected by this deprecation: GitLab.com users, Self-managed users, or Dedicated users? (choose all that apply)
-
GitLab.com -
Self-managed -
Dedicated
Note: This feature is distributed through CI/CD templates.
What pricing tiers are impacted?
-
GitLab Free -
GitLab Premium -
GitLab Ultimate
Note: The impact is primarily on Ultimate customers because they will be the most active users of SAST results and may have policies or other practices in place. However, most customers do not actively customize analyzer behavior in this way.
-
Internal note outlining details of customer impact has been created
Deprecation Milestone
This deprecation will be announced in milestone: 17.9 If this deprecation has already been announced, include information about when the initial announcement went out and what follow-up announcements are scheduled.
Planned Removal Milestone
The feature / functionality will be removed in milestone: 18.0
Links
Checklists
Timeline
Rollout Plan
-
DRI Engineers: @thiagocsf
-
DRI Engineering Manager: @thiagocsf
-
Describe rollout plans on GitLab.com -
Link to a feature flag rollout issue that covers: -
Expected release date on GitLab.com and GitLab version -
Rollout timelines, such as a percentage rollout on GitLab.com -
Creation of any clean-up issues, such as code removal
-
-
-
Determine how to migrate users still using the existing functionality -
Document ways to migrate with the tooling available -
Automate any users who have not yet migrated, but ensure it's a two-way door decision
Communication Plan
- DRI Product Manager: @connorgilbert
An internal slack post and a release post are not sufficient notification for our customers or internal stakeholders. Plan to communicate proactively and directly with affected customers and the internal stakeholders supporting them.
Internal Communication Plan
-
Create an internal note in the comment thread of this issue with a comprehensive narrative of customer impacts, with the intended audience of internal stakeholders who directly interact with customers. - Consider: what will the CSM / AE / SA teams need to tell their customers? What will they want to know about customer sentiment and impact?
- If customers must take an action, include in this internal note the following information: what action is needed, the steps they can take to complete it, the due date for that action, and the consequences of not completing the action in time.
- #519133 (comment 2342893628)
-
Internal announcement plan (timeline for notifications, audience, channels, etc) -
Support and enablement plan - Support readiness: Document how the support team should handle tickets related to this deprecation / breaking change.
- Customer Success readiness: Ensure the CS team knows how to bring questions or concerns from clients to the right internal team members.
External Communication Plan
-
Customer announcement plan (timeline for notifications, audience, channels, etc) -
Ensure you have approvals from legal and corp comms for any communication being sent directly to customers. -
As soon as possible, but no later than the third milestone preceding the major release, ensure that the following are complete (for example, given the following release schedule: 17.8, 17.9, 17.10, 17.11, 18.0–17.9is the third milestone preceding the major release).-
A deprecation announcement entry has been created so the deprecation will appear in release posts and on the general deprecation page. -
Documentation has been updated to mark the feature as deprecated. - Analyzers have been explicitly marked EoS since the EoS dates.
-
-
On the major milestone: -
The deprecated item has been removed. Add link to the relevant merge request. -
If the removal of the deprecated item is a breaking change, the merge request is labeled breaking change. -
Document the migration plan for users, clearly outlining the actions they need to take to mitigate the impact of the breaking change.
-
Development
-
DRI Engineers: @thiagocsf
-
DRI Engineering Manager: @thiagocsf
-
Measure usage of the impacted product feature -
Evaluate metrics across GitLab.com, Self-Managed, Dedicated -
add issue link -
list any metrics and/or dashboards
-
-
Create tooling for customers to manually migrate their data or workflows -
add issue link
-
-
Build mechanism for users to manually enable the breaking change ahead of time -
add issue link
-
-
Automate the migration for those who do not take any manual steps (ensure the automation can be reverted) -
add issue link
-
-
Develop rollout plan of breaking change on GitLab.com -
add feature flag rollout issue
-
-
Dogfood the changes on GitLab.com or a Self-Managed test instance -
add issue link
-
-
(Optional) Create UI controls for instance admins to disable the breaking change, providing flexibility to Self-Managed / Dedicated customers. Optional as this depends on the breaking change. -
add issue link
-
Approvals
-
Product Manager @connorgilbert -
Engineering Manager @thiagocsf -
Senior Engineering Manager / Director @twoodham -
Group / Director of Product Management @sarahwaldner -
Product / Eng Leaders in the CPOorCTOorganizations, as applicable (optional - depends on scope of change)
Keep in mind that approval check boxes and deprecations notices alone are not sufficient communication about breaking changes. Despite having approvals documented here, the PM/EM will still need to take active steps to partner with internal stakeholders and customers to ensure a positive user experience.
Stakeholder Mentions
-
Product Designer (None) -
Tech Writer @rdickenson -
Software Engineering in Test @willmeek -
Any other stable counterparts based on the product categories: -
Add Sales/CS counterpart or mention @timtams -
Add Support counterpart or mention @gitlab-com/support/managers@cmutua -
Add Marketing counterpart or mention @martin_klaus: @sladha -
Add Corp comms if direct customer comms are needed @jmalleo: not required -
Add Product Security counterpart, if relevant to your deprecation: not required -
Mention (in internal note) Customer Success Managers / Acount Managers / Solutions Architects for impacted customers
-
Labels
-
This issue is labeled deprecation, and with the relevant ~devops::,~group::, and~Category:labels. -
This issue is labeled breaking change if the removal of the deprecated item will be a breaking change.