Skip to content

GitLab Next

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 39,511
    • Issues 39,511
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
  • Merge requests 1,223
    • Merge requests 1,223
  • Requirements
    • Requirements
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Packages & Registries
    • Packages & Registries
    • Container Registry
  • Analytics
    • Analytics
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
    • Value stream
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.org
  • GitLabGitLab
  • Merge requests
  • !50872

Merged
Created Jan 05, 2021 by rossfuhrman@rossfuhrmanDeveloper0 of 13 tasks completed0/13 tasks

Migrate from SAST_DEFAULT_ANALYZERS to SAST_EXCLUDED_ANALYZERS

  • Overview 31
  • Commits 3
  • Pipelines 5
  • Changes 10

What does this MR do?

Adds support for SAST_EXCLUDED_ANALYZERS to the SAST vendored template. We are also maintaining backwards compatible support for SAST_DEFAULT_ANALYZERS during a deprecation period. SAST_DEFAULT_ANALYZERS will be removed in %14.0 with Remove SAST_DEFAULT_ANALYZERS.

SAST_EXCLUDED_ANALYZERS allows customers to specify which SAST analyzers they do not want to run, as opposed to the old way where they would need to use SAST_DEFAULT_ANALYZERS to list all the analyzers they wanted to run.

Configuring SAST in the UI has also been updated to support SAST_EXCLUDED_ANALYZERS while also maintaining backwards compatible support for SAST_DEFAULT_ANALYZERS.

Screenshots (strongly suggested)

Local screenshot of using the updated SAST Configuration UI where the only change was checking/unchecking analyzers. This demonstrates the old SAST_DEFAULT_ANALYZERS variable is read and the SAST_EXCLUDED_ANALYZERS is written. Screen_Shot_2021-01-10_at_9.11.53_PM

Does this MR meet the acceptance criteria?

Conformity

  • Changelog entry
  • Documentation (if required)
  • Code review guidelines
  • Merge request performance guidelines
  • Style guides
  • Database guides
  • Separation of EE specific content

Availability and Testing

  • Review and add/update tests for this feature/bug. Consider all test levels. See the Test Planning Process.
  • Tested in all supported browsers
  • Informed Infrastructure department of a default or new setting change, if applicable per definition of done

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Related to #229974 (closed)

Edited Jan 11, 2021 by rossfuhrman
Assignee
Assign to
Reviewer
Request review from
Time tracking
Source branch: 229974-migrate-to-SAST_EXCLUDED_ANALYZERS

Enable Gitpod?

To use Gitpod you must first enable the feature in the integrations section of your user preferences.

Cancel Enable Gitpod