Skip to content

Draft: Improve Vulnerability Tracking: EE Development Documentation

James Johnson requested to merge improve_vuln_tracking-documentation into master

THIS MR IS CLOSED - THE BRANCH NEEDED TO BE RENAMED TO HAVE docs IN THE NAME. See !52942 (closed) instead

This MR is the EE development documentation portion of the proof-of-concept MR: !45339 (closed) and is part of the epic https://gitlab.com/groups/gitlab-org/-/epics/4690 - Improve Vulnerability Tracking: MVP: Scope+Offset

What does this MR do?

This MR adds EE development documentation that explains:

  • The architecture and workflow of tracking fingerprints
  • How vulnerabilities are correlated when they have multiple tracking fingerprints

Screenshots (strongly suggested)

TODO

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by James Johnson

Merge request reports