Framework for source code rules
Opportunity to investigate
---
GitLab offers a number of controls that can be implemented as safeguards. These controls can be put in place to keep changes from having a negative or enforce adherence to policies. Integrating features like protected branches, approval rules, code owners (approvals) and soon “status checks” should have an experience that easy to set up, maintain, and consume downstream.
Walkthrough video
---
- :tv: Overview - https://youtu.be/oe-Gg5B1BXA (Recorded 4-17-2022)
- Q&A - https://gitlab.zoom.us/rec/share/vBbQ1KcB5JJRaXsplH4NDpNyK1Uy9iqKegBM2OpBwGXm-oEw2GCnxOsCjxLm_GGM.q9t3ctyXVXfTRRFC
Research insights
---
- [Video walk through of the CM Scorecard Recommendations - Create:Source Code:Code Review FY21-Q2](https://youtu.be/d32NIDcLewc) (see video description for chapter markers and references)
- Issues related to [CM Scorecard Recommendations - Create:Source Code:Code Review FY21-Q2](https://gitlab.com/gitlab-org/gitlab-design/-/issues/1374)
- Specific issue: [Improve the organization of repository and merge request policy settings](https://gitlab.com/gitlab-org/gitlab/-/issues/258577). Explanation of the severity of the issue: https://gitlab.com/gitlab-org/gitlab/-/issues/258577#note_450874492
- Approvals, Code owners, and push/merge restriction have a high occurrence when surveyed about "What <plan> plan features contributed to your decision to purchase a subscription". [Post Purchase Survey Q4 FY21](https://docs.google.com/presentation/d/1BCDjnZsZpXGGcjFFpPeR7ICV8EwiUHNJ1qoBtrXpFCQ/edit#slide=id.g59bfc474c5_2_145)
- Insights from [Paid Net Promoter Score (PNPS) Q2 FY23 Report date: August 2022](https://docs.google.com/presentation/d/13pkZne6go_mjLFr-azLdcufHHpf17wN_u-ubRhHiUco/edit#slide=id.g816461913c_1_61):
- Quotes from passive (p. 15):
- “GitLab works fine overall, but it is sometimes hard to find what you are looking for, especially when it comes to settings.”
- "What I still hear from developers is that they prefer Github for the reason of more simplicity in the frontend."
- “It’s good, very configurable, but is a bit complex and the docs are not perfect.”
- “User experience is not clean. Seems very cluttered. Bitbucket has relatively clean UI. But GitLab has good features.”
Feature comparison
---
Figma :point_right: https://www.figma.com/file/NKRTU2J6fsprk0dHq20NVy/Integrate-the-experience-for-safeguards?node-id=2%3A0

🤝 Cross-stage Collaboration
---
cc gitlab~16934793
cc gitlab~12052083
cc ~"group::compliance"
<!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION -->
*This page may contain information related to upcoming products, features and functionality.
It is important to note that the information presented is for informational purposes only, so please do not rely on the information for purchasing or planning purposes.
Just like with all projects, the items mentioned on the page are subject to change or delay, and the development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.*
<!-- triage-serverless v3 PLEASE DO NOT REMOVE THIS SECTION -->
epic