Add security bot comment for policy violations in MRs
What does this MR do and why?
This MR adds security bot comments for policy violations in MRs.
This change introduces an automatic comments on the MRs where security policy violations are detected. It adds guidance for the user on what to do next with regards to the needed approvals.
The comments are created by security bot. We may switch to a dedicated security policy bot from #394958 (closed), but for the moment, we plan to test this feature with the security bot.
This feature is added behind a feature flag.
Screenshots or screen recordings
With violations:
Resolved violations:
Recording:
How to set up and validate locally
Numbered steps to set up and validate the change are strongly suggested.
-
Enable the feature flags in the rails console:
Feature.enable(:security_policy_approval_notification)
-
Add secret detection template into
.gitlab-ci.yml
:include: - template: Jobs/Secret-Detection.gitlab-ci.yml test-job: script: - echo "Test Job..."
-
Create a new project with a security policy. Example:
type: scan_result_policy name: Secrets description: '' enabled: true rules: - type: scan_finding branches: [] scanners: - secret_detection vulnerabilities_allowed: 0 severity_levels: - critical - high - medium - low - unknown - info vulnerability_states: - new_needs_triage - new_dismissed actions: - type: require_approval approvals_required: 1 user_approvers_ids: - 4
-
Introduce a policy violation in an MR - for example, add a secret which would trigger secret detection scanner from a policy.
-
After the CI has finished, observe an automatic comment being added.
-
Add a new commit which doesn't fix the violation yet. There shouldn't be any new automatic comment.
-
Add a new commit, fixing the violation.
-
The comment should get updated and say that violations have been fixed.
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
-
I have evaluated the MR acceptance checklist for this MR.
Related to #411656 (closed)
Merge request reports
Activity
changed milestone to %16.1
assigned to @mcavoj
added 1 commit
- 0f6ca51f - Add security policy bot comment for policy violations in MRs
- A deleted user
added feature flag label
1 Warning featureaddition and featureenhancement merge requests normally have a documentation change. Consider adding a documentation update or confirming the documentation plan with the Technical Writer counterpart.
For more information, see:
- The Handbook page on merge request types.
- The definition of done documentation.
Reviewer roulette
Changes that require review have been detected!
Please refer to the table below for assigning reviewers and maintainers suggested by Danger in the specified category:
Category Reviewer Maintainer backend Hordur Freyr Yngvason (
@hfyngvason
) (UTC-4)John Mason (
@john-mason
) (UTC-4)To spread load more evenly across eligible reviewers, Danger has picked a candidate for each review slot, based on their timezone. Feel free to override these selections if you think someone else would be better-suited or use the GitLab Review Workload Dashboard to find other available reviewers.
To read more on how to use the reviewer roulette, please take a look at the Engineering workflow and code review guidelines. Please consider assigning a reviewer or maintainer who is a domain expert in the area of the merge request.
Once you've decided who will review this merge request, assign them as a reviewer! Danger does not automatically notify them for you.
Sidekiq queue changes
This merge request contains changes to Sidekiq queues. Please follow the documentation on changing a queue's urgency.
These queues were added:
security_generate_policy_violation_comment
If needed, you can retry the
danger-review
job that generated this comment.Generated by
Dangermentioned in commit gitlab-org-sandbox/gitlab-jh-validation@96f31f83
Allure report
allure-report-publisher
generated test report!e2e-test-on-gdk:
test report for 4c675c56expand test summary
+-----------------------------------------------------------------------+ | suites summary | +------------------+--------+--------+---------+-------+-------+--------+ | | passed | failed | skipped | flaky | total | result | +------------------+--------+--------+---------+-------+-------+--------+ | Plan | 4 | 0 | 0 | 0 | 4 | ✅ | | Create | 8 | 0 | 1 | 0 | 9 | ✅ | | Data Stores | 2 | 0 | 0 | 1 | 2 | ❗ | | Govern | 2 | 0 | 0 | 0 | 2 | ✅ | | Monitor | 4 | 0 | 0 | 0 | 4 | ✅ | | Manage | 1 | 0 | 0 | 0 | 1 | ✅ | | Framework sanity | 0 | 0 | 1 | 0 | 1 | ➖ | +------------------+--------+--------+---------+-------+-------+--------+ | Total | 21 | 0 | 2 | 1 | 23 | ❗ | +------------------+--------+--------+---------+-------+-------+--------+
e2e-package-and-test:
test report for 4c675c56expand test summary
+-------------------------------------------------------------+ | suites summary | +--------+--------+--------+---------+-------+-------+--------+ | | passed | failed | skipped | flaky | total | result | +--------+--------+--------+---------+-------+-------+--------+ | Govern | 96 | 2 | 2 | 10 | 100 | ❌ | +--------+--------+--------+---------+-------+-------+--------+ | Total | 96 | 2 | 2 | 10 | 100 | ❌ | +--------+--------+--------+---------+-------+-------+--------+
added 1 commit
- 60a33532 - Add security policy bot comment for policy violations in MRs
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@98cc4a97
added 1 commit
- ede84272 - Add security policy bot comment for policy violations in MRs
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@a5574a23
mentioned in issue #411656 (closed)
- Resolved by Andy Schoenen
added 899 commits
-
ede84272...3e1adf23 - 898 commits from branch
master
- 35829838 - Add security bot comment for policy violations in MRs
-
ede84272...3e1adf23 - 898 commits from branch
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@342c7488
added 1 commit
- 5016c40e - Add security bot comment for policy violations in MRs
added 1 commit
- 7e0335c4 - Add security bot comment for policy violations in MRs
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@72393783
- Resolved by Andy Schoenen
@Andysoiron I switched to using the security bot here. Could you please do the initial review?
requested review from @Andysoiron
added 1 commit
- d81482e9 - Add security bot comment for policy violations in MRs
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@7879c2e0
- Resolved by Martin Čavoj
- Resolved by Andy Schoenen
- Resolved by Martin Čavoj
- Resolved by Martin Čavoj
removed review request for @Andysoiron
added Technical Writing label
- Resolved by Russell Dickenson
requested review from @rdickenson
added 1 commit
- d4bc812e - Add security bot comment for policy violations in MRs
requested review from @Andysoiron
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@d1561c3a
@rdickenson
, thanks for approving this merge request.This is the first time the merge request is approved. To ensure full test coverage, a new pipeline will be started shortly.
For more info, please refer to the following links:
added pipeline:mr-approved label
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@9a3242c7
- Resolved by Martin Čavoj
added 457 commits
-
d4bc812e...653d821c - 456 commits from branch
master
- f3269f40 - Add security bot comment for policy violations in MRs
-
d4bc812e...653d821c - 456 commits from branch
mentioned in commit gitlab-org-sandbox/gitlab-jh-validation@820d57f9