Merge Request Improvements (Baselines)
# Purpose This epic is designed to track progress and updates to the MR following the Baseline Evaluation & Recommendations. ## Background From the [Baseline Evaluation](https://gitlab.com/gitlab-org/gitlab-design/issues/479) Inherent workflow issues overshadowed other experience shortcomings enough for a complete reconsideration of the entire security workflow with the MR. ### Problem to solve: How might we create a workflow that simplifies the remediation process and is inclusive to all users no matter their security ability? ### Proposal: #### Solution idea 1: Define areas of the MR for appropriate security information consumption and action. Concept a new security workflow that is meant to address vulnerabilities detected in changes from the commits only. 1. Change the security widget from an action area to an overview area. 2. Move vulnerability actions to the bottom tabs of the MR and leverage existing code review experience to create a security code review process. 3. Bonus: Consider incremental/targeted security testing coupled with a security testing strategy, instead of full branch scans depending on the type of scan being done. [See this issue](https://gitlab.com/gitlab-org/gitlab-ee/issues/12857) | Today | Tomorrow | | ------ | ------ | | ![Screen_Shot_2019-07-16_at_3.43.04_PM](/uploads/c5866afe6373d6e7ccfbc135d0cc1f09/Screen_Shot_2019-07-16_at_3.43.04_PM.png) | ![Screen_Shot_2019-07-16_at_3.39.04_PM](/uploads/01e97d2081000e1b0c2729e0777512b0/Screen_Shot_2019-07-16_at_3.39.04_PM.png) | ### Plan ![Screen_Shot_2019-07-17_at_2.13.18_PM](/uploads/027c55270fe5cc5c645b08a69faa5fb9/Screen_Shot_2019-07-17_at_2.13.18_PM.png)
epic