Loading
Add categories to security attributes removal re-sync process
What does this MR do and why?
As described in #596003 (closed), when the security attribute is removed from the project, the MR was still blocked. In MR !230801 (merged) added a trigger to re-sync policies when security attributes are removed for policies with the business_impact scope .
In this MR we are extending the re-sync trigger for the others security categories policy scope. During the tests, the bot comment was not updated. I will investigate and work in a fix in a follow-up MR.
References
Related to: #596003 (closed)
How to set up and validate locally
- Create a new group
- Go to Secure > Security configuration
- Select any category other than Business Impact. E.g Application
- Click in Create attribute
- Add a name and description E.g Finance
- Click in Save changes
- Create a new project
- Add a
.gitlab-ci.ymlfile to the project with the content:
include:
- template: Jobs/SAST.gitlab-ci.yml- Add an empty
test.rbfile - Go to Secure > Security configuration
- Select Security attributes
- Click on Edit project security attributes
- Select the attribute created in the previous steps. E.g:
Finance - Click in save changes
- Go back to the group created on step 1
- Go to Secure > Policies
- Click on New policy
- Select Merge request approval policy
- Create a policy to block new vulnerabilities on
Financeprojects - Get the
security_attributeid
category = Security::Category.where(template_type: "application").where(namespace: Group.last)
security_attribute_id = Security::Attribute.where(security_category: category).where(name: "Finance").first- Create a policy like
approval_policy:
- name: Test
description: ''
enabled: true
rules:
- type: scan_finding
branches: []
vulnerabilities_allowed: 0
severity_levels: []
vulnerability_states: []
scanners:
- type: sast
vulnerabilities_allowed: 0
severity_levels:
- critical
- high
vulnerability_states:
- new_needs_triage
vulnerability_attributes:
false_positive: false
policy_scope:
application:
including:
- id: <security_attribute_id>
actions:
- type: require_approval
approvals_required: 1
role_approvers:
- developer- Click on Create new project with the new policy
- Merge the MR to add the policy
- Go back to the project created in step 7
- Create a MR adding the file
vuln.rbwith the content
class RunScript
def run_script
system("cat #{params[:path]}")
end
end- Verify the MR is blocked
- Go to Secure > Security Configuration
- Select Security attributes
- Click on Remove attribute
- Verify the MR does not require approval anymore
- Repeat the steps 5 to 8 to add the security attribute again
- Verify the MR is blocked again
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Marcos Rocha
