Skip to content

Add minimal list of requirements for SAST analyzers

Thomas Woodham requested to merge 0324-sast-analyzer-features into master

What does this MR do?

SAST, as a feature category, has a rather large list of features. However, we had not previously documented the features which belong specifically to SAST analyzers. This MR attempts to articulate this information and declare a minimum feature set a new analyzer must have for it to be declared generally available.

Screenshots (strongly suggested)

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Merge request reports