Skip to content

Make issue created from vulnerability feedback confidential

What does this MR do?

This is the first step to ensure more privacy for vulnerability management. The vulnerability information should be confidential until a patch is released, so customers' applications are more protected against unauthorized access.

Proposal

When creating a new issue from a vulnerability, the issue is created as confidential.

This is applied to the following flows:

  1. Group Security Dashboard

  2. Project Security Dashboard

  3. Merge Request Security Reports

  4. Pipeline Security Reports

What are the relevant issue numbers?

#8725 (closed)

Does this MR meet the acceptance criteria?

Closes #8725 (closed)

Edited by Kamil Trzciński

Merge request reports