Project Vulnerability Report setting to look at an individual branch

Issue Update

This issue has been closed in favor of tracking its parent epic: Track Vulnerabilities in locations other than t... (&3430)

Problem to solve

The Security Dashboard today displays results for the master branch, but it is not straightforward to only look at security results for a specific branch.

Intended users

  • Delaney (Development Team Lead)
  • Sasha (Software Developer)
  • Sidney (Systems Administrator)
  • Sam (Security Analyst)

Further details

Proposal

Provide a mechanism on the Project Vulnerability Report to select a specific branch to display results for on the security dashboard. Default to default branch (master).

Also add public API(s) to enable pulling vulnerability finding information for branches other than default, similar to https://docs.gitlab.com/ee/api/vulnerability_findings.html

Permissions and Security

Documentation

  • Update Project Vulnerability Report screenshots and information detailing new branch switching behavior
  • Update or extend https://docs.gitlab.com/ee/api/vulnerability_findings.html to cover API changes for non-default branch findings

Testing

What does success look like, and how can we measure that?

What is the type of buyer?

Links / references

Edited Jul 16, 2025 by Tim Poffenbarger
Assignee Loading
Time tracking Loading