Skip to content

Update SAST analyzers flawfinder severity/confidence

What does this MR do?

With the work in &4004 (closed) we are looking to improve the quality of our scanner results by including severity in all analyzers. After reviewing flawfinder it looks like we should be reporting the previous confidence value as severity. This work is done with gitlab-org/security-products/analyzers/flawfinder!32 (merged) and will require an update to the data table to reflect this

Screenshots

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Merge request reports