Security Insights 18.2 Planning Issue
Priority Features and Maintenance
| Areas of focus | Committed | DRI | Delivery Scope for current milestone | Completion Milestone | Status (mid-milestone checkpoint) |
|---|---|---|---|---|---|
|
|
frontend: @lorenzvanherwaarden dependency of: groupsecurity infrastructure commit slide |
18.2 |
|
||
|
|
stage: implementation backend: @wandering_person frontend: @sming-gitlab dependency: no |
18.2 |
|
||
|
|
stage: implementation frontend: @dpisek @lorenzvanherwaarden backend: @charlieeekroon @subashis dependency: groupsecurity infrastructure |
Q3 / 18.5 |
|
||
|
Support Reachability Filters on Vulnerability R... (&17251 - closed) |
|
stage: implementation frontend: @svedova dependency of: groupcomposition analysis |
18.2 |
|
|
|
MVC: Enable Diff-Based Scanning in MRs for Fast... (&17758 - closed) |
|
stage: implementation backend: @bwill frontend: @svedova dependency of: groupstatic analysis |
18.3 |
|
Priority Features - Rollout Phase
| Areas of focus | Committed | DRI | Delivery Scope for current milestone | Completion Milestone | Status (mid-milestone checkpoint) |
|---|---|---|---|---|---|
|
Database migration to correct vulnerabilities incorrectly transitioned by auto-resolve |
|
Support CR stage | 18.1 |
|
|
|
Migrate dependency list to GraphQL: Project-level (&17253 - closed) |
|
backend: @charlieeekroon frontend: @dpisek |
Rollout on internal test projects | 18.0 |
|
Bugs / Secondary Features / Maintenance
| Areas of focus | Committed | DRI | Delivery Scope for current milestone | Completion Milestone | Status (mid-milestone checkpoint) |
|---|---|---|---|---|---|
|
Vulnerability Widget incorrectly shows existing... (#468324 - closed) |
|
stage: bug analysis backend: @bwill |
|
18.1 |
|
|
Investigate and find the reason why vulnerabili... (#549381) |
|
stage: bug fix backend: @subashis |
18.2 |
|
|
|
Vulnerability severity is sometimes not updated... (#548960 - closed) |
|
stage: bug fix backend: @bwill |
|
|
|
|
Error during SBoM ingestion: Validation failed:... (#543113 - closed) |
|
stage: bug fix backend: @subashis |
|
18.2 |
|
|
|
stage: implementation frontend: @dpisek |
|
18.2 |
|
|
|
Group Security Dashboard - Project security sta... (#545479 - closed) |
|
stage: implementation backend: @uokeadu |
|
18.2 | |
|
backend: @subashis frontend: 18.3 stage: knowledge transfer on ES integration / POC implementation |
18.4 |
|
|||
|
Manual vulnerability severity overrides - Hando... (#524406 - closed) |
|
stage: knowledge transfer backend: @uokeadu frontend: @svedova dependency: groupsecurity platform management |
18.2 |
Remaining scope tracked in new epic Post-MVC: Manual Vulnerability Severity Overrides (&18344) |
Estimation Projects
| Areas of focus | DRI | Completion Milestone | Status (mid-milestone checkpoint) |
|---|---|---|---|
| Estimation Issue: Implement EPSS / KEV / CVSS F... (#547746 - closed) | backend: @subashis | 18.4 | |
| Add Reachable to Vulnerability Report CSV Export (#517840) | backend: TBD | Q3 / TBD | |
| Estimation: Filter Data to Releasing Branches (#547798) | backend: TBD | Q4 / TBD | |
Full list of estimation issues powered by GLQL
display: table
fields: title, assignees
query: label = "group::security insights" AND label = "estimation:needed"
Team member focuses
Secondary Projects and Issues
Planned / Planning
-
Use graphql search for project names for attach... (#521600 - closed)
🟢 complete - Add Scanner to Report Type column header. Add t... (#526093 - closed) - workflowrefinement
Unplanned
- Claude 4.5 Sonnet Vulnerability Resolution Roll... (#545698) - dependency on groupstatic analysis for CWE testing
typemaintenance
Unplanned
- Migrate dependency filtering to GraphQL: Group-... (&17254)
- [Feature flag] Cleanup version_filtering_on_pro... (#548592 - closed) • Subashis Chakraborty • 18.2
- [Feature flag] Cleanup version_filtering_on_gro... (#548593 - closed) • Subashis Chakraborty • 18.2
typebug
Planned / Planning
- https://gitlab.com/gitlab-org/gitlab/-/issues/550123+ severity2
- https://gitlab.com/gitlab-org/gitlab/-/issues/550347+ severity2
Unplanned
- Inconsistent badges on dismissed vulnerabilities (#549715) severity2
- Referesh vulnerability_statistics following SAS... (#533973) - group assignment / capacity
Full bug list powered by GLQL
display: table
fields: title, labels("Severity::*"), healthStatus, assignees
query: label = "group::security insights" AND label = "type::bug" AND milestone = "18.2"
New Items to Discuss
What's on the horizon?
18.2 Release Post Candidates
Developer Advocacy
Features or maintenance items that the team would like to work on, where possible.
Prior items are now tracked in the internal slide deck.
| Issue | Why | Type | BE/FE | Scope | Advocates |
|---|---|---|---|---|---|
| Migrate dependency filtering to GraphQL: Group-... (&17254) | Group level support now that Project level is complete. Removes tech-debt. Unblocks addition of project filters | typemaintenance | both | @sming-gitlab @dpisek @lorenzvanherwaarden | |
| Verification projects inventory | Re-inventory of implementation and verification projects | @nmccorrison | |||
| Secure section terminology (#521394 - closed) | Maintain consistency in Secure terminology | typemaintenance | FE | @charlieeekroon |