Skip to content

Add link to standalone vulnerabilities page on Dependency List

Jannik Lehmann requested to merge jnnkl-vuln-link-on-dependency-page into master

What does this MR do?

This MR solves #321715 (closed) There is now a link to the vulnerability standalone page on the dependency List.

Corresponding Backend Issue: !56394 (merged)

The feature is currently behind a feature flag (standaloneVulnDependencyList) Rollout Issue

How to reproduce?

  1. enable the feature flag

echo "Feature.enable(:standalone_vuln_dependency_list)" | rails c

  1. go find a Project with vulnerabilites in the dependency list, for example: https://gitlab.com/gitlab-examples/security/security-reports

  2. Go to Security & Compliance -> Dependency List & click the chevron the expand a Dependency

Screenshots (strongly suggested)

before after
Screenshot_2021-03-17_at_11.42.34 Screenshot_2021-03-17_at_11.39.51

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Jannik Lehmann

Merge request reports