Show Needs triage instead of DETECTED in finding modals
What does this MR do and why?
Related #434128 (closed)
"Needs triage" has been shown as label for the detected
state on vulnerabilities for a while and it makes sense to extend this for findings too in the finding modal. This MR changed the old and new finding modal such that it uses the StatusBadge component which renders the correct translation of the status and correct badge color when the status is provided.
MR acceptance checklist
Please evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Screenshots or screen recordings
Screenshots are required for UI changes, and strongly recommended for all other merge requests.
Before | After |
---|---|
How to set up and validate locally
Prerequisites
- You need an EE license
- You need to have runners enabled (See $2408961 for setting up a runner)
- Import https://gitlab.com/gitlab-examples/security/security-reports
- Run a pipeline on master
Validate
New modal
- Go to a pipeline > security tab > click on a finding
- This shows the new finding modal. Validate that it shows "Needs triage" when in the detected status.
- Dismiss the finding and open the modal again. Validate that is shows a grey background for the dismissed status.
Old modal
- Import https://gitlab.com/gitlab-org/govern/demos/sandbox/minac/test-remediations
- Do not run a pipeline yet on master!
- In the imported test-remediations project
- go to
reports/sast.json
and remove both entries invulnerabilities
, leaving effectively an empty array - commit and push this to master
- now, in
reports/sast.json
, add the removed vulnerabilities back again, but commit and push to a new branch, and create a merge request.
- go to
- In the MR, expand the security scanning widget and click on any finding
- This shows the old modal.
- Validate that it shows "Needs triage" when in the detected status.
- Dismiss the finding and open the modal again. Validate that is shows a grey background for the dismissed status.
Edited by Lorenz van Herwaarden