Skip to content

Vulnerabilities API returns non-dismissed vulnerabilities by default

What does this MR do?

Secondary MR for #10544 (closed) to add additional scoping to the new Vulnerabilities API.

  • Scope default response to non-dismissed vulnerabilities (dismissed accessible via scope=all param)
  • Support filtering by severity and confidence

Does this MR meet the acceptance criteria?

Conformity

Performance and testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Lucas Charles

Merge request reports