Threat Insights priorities
### Purpose
This issue is for high-level prioritization of gitlab~10690752 items. It primarily includes feature/product items and is not a comprehensive list of everything that will be worked such as bugs, implementation issues, documentation, or technical debt. It is not intended as a replacement or alternative for our issue boards. It is meant as an easily consumable single view of the main in-progress and upcoming work items for the Threat Insights group. It also allows mixing Epics and Issues in a single list.
This list is not a guarantee of timing or order of delivery. Rather, use this as a guide to see the tops items we are working on and will be in the near future. The list purposefully does not extend out many milestones into the future to maintain focus and not set a false sense of priority. If you don't see an issue or Epic you are interested in, please check the [Vulnerability Management category vision Epic](https://gitlab.com/groups/gitlab-org/-/epics/3304) for a full list.
### Priorities
Possible statuses:
- Not started: no implementation issues should be scheduled. There is likely a Design issue in progress, and there may be issues in planning breakdown. We may have implementation issues if we're planning to start it soon.
- Started: the scope of the epic should be locked-down, and we have implementation issues scheduled.
- Complete: epic is code complete and is in production but may be behind a feature flag. The epic may contain open issues; in this case the issues may be moved to a new epic.
Complete items are removed from the table once the code is in production without a feature flag, and a release post, if applicable, has been merged. The epic is closed at this point.
| priority | name | BE DRI | FE DRI | Status | Comment |
| ------ | ------ | ------ | ------ | ------ | ------- |
| 1 | [Integrate developer security training 2.0](https://gitlab.com/groups/gitlab-org/-/epics/7805) | @subashis | @sming-gitlab | Started |
| 2 | [Enforce validation of security reports](https://gitlab.com/groups/gitlab-org/-/epics/6968) | @Quintasan | @dpisek | Started |
| 3 | [Deprecate and remove `Vulnerabilities::Feedback`](https://gitlab.com/groups/gitlab-org/-/epics/5629) | @subashis | N/A | Started | 1 BE for 3 Milestones. |
| 4 | [ Migrate Pipeline Security Tab to GraphQL](https://gitlab.com/groups/gitlab-org/-/epics/8054) | @jschafer | @dpisek | Started | Help wanted: 1 BE for <1 Milestone, 0 FE |
| 5 | [Vulnerability Management DDL to replace raw JSON in the DB (`raw_metadata`)](https://gitlab.com/groups/gitlab-org/-/epics/4239) | @jschafer | N/A | Started |
| 6 | [Deprecate `project_fingerprint`](https://gitlab.com/groups/gitlab-org/-/epics/2791) | @minac | N/A | Started | Help wanted: 1 BE for 1 Milestone. |
| 7 | [Vulnerability GraphQL resource to access a single vulnerability](https://gitlab.com/groups/gitlab-org/-/epics/3657) | @jschafer | @dpisek | Not started | Help wanted: 1 BE for <1 Milestone, 0 FE |
| 8 | [Vulnerability bulk status updates](https://gitlab.com/groups/gitlab-org/-/epics/4649) (blocked by &5629) | @Quintasan | @svedova | Not started |
| 9 | [Dismissal types / reasons](https://gitlab.com/groups/gitlab-org/-/epics/4942) (blocked by &5629) | @Quintasan | @svedova | Not started |
| 10 | [Auto-resolve vulnerabilities when not found in subsequent scans](https://gitlab.com/groups/gitlab-org/-/epics/5708) (blocked by &5629) | @minac | | Not started |
| 11 | [Allow filtering vulnerability dashboard by non-remediated activity](https://gitlab.com/groups/gitlab-org/-/epics/7883) | | | Not started | |
| 12 | [Enhanced filtering and basic search of Vulnerability lists](https://gitlab.com/groups/gitlab-org/-/epics/3429) | | | Not started | |
| 13 | [Audit users can access all Vulnerability Management features](https://gitlab.com/gitlab-org/gitlab/-/issues/323858) | | | Not started | |
| 14 | [Display vulnerabilities by age in Security Dashboards](https://gitlab.com/groups/gitlab-org/-/epics/5354) | @jschafer | @svedova | Not started | |
| 15 | [Include Additional Information in Security Dashboard Export](https://gitlab.com/gitlab-org/gitlab/-/issues/272486) | @subashis | | Not started | |
| 16 | [Group-level Security Dashboard: Security scanner status widget](https://gitlab.com/gitlab-org/gitlab/-/issues/262079) | | | Not started | |
| 17 | [Deprecate vulnerability REST APIs](https://gitlab.com/groups/gitlab-org/-/epics/5118) | @subashis | | Not started | |
| 18 | [Prepare for JIRA custom domains](https://gitlab.com/groups/gitlab-org/-/epics/5911) | @Quintasan | | Not started | |
| 19 | [Use `report_type` in vulnerability report's Too](https://gitlab.com/gitlab-org/gitlab/-/issues/341465) | @minac | TBD | Not started | |
| 20 | [Vulnerability::IssueLink migration](https://gitlab.com/groups/gitlab-org/-/epics/4167) | @Quintasan | TBD | Not started | |
| 21 | [Remove the `Security::PipelineVulnerabilitiesFinder` class](https://gitlab.com/gitlab-org/gitlab/-/issues/334488) | TBD | | Not started | Help wanted: 1 BE for <1 Milestone. |
| 22 | [[Feature flag] Enable description of feature createVulnerabilityJiraIssueViaGraphql](https://gitlab.com/gitlab-org/gitlab/-/issues/329780) | | @dpisek | Not started | |
| 23 | [Use merge base for security MR widget](https://gitlab.com/gitlab-org/gitlab/-/issues/295167) | various; see sub-Epics | | Not started | Help wanted: 1 BE for 1 Milestone. |
| 24 | [Improve performance for Vulnerability Report](https://gitlab.com/groups/gitlab-org/-/epics/5770) | TBD | N/A | Not started | |
| 25 | [Improve the performance of `vulnerabilitySeveritiesCount`](https://gitlab.com/gitlab-org/gitlab/-/issues/324393) | TBD | | Not started | Help wanted: 1 BE for 1 Milestone. |
| 26 | [Only load MR security widget findings after clicking "Expand"](https://gitlab.com/gitlab-org/gitlab/-/issues/344467) | TBD | | Not started | Help wanted: 1 BE, 1 FE for <1 Milestone. |
| 27 | [Limits for security reports artifact size](https://gitlab.com/gitlab-org/gitlab/-/issues/331679#note_631687667) | TBD | | Not started | |
| 28 | [MR Security widget refactor](https://gitlab.com/groups/gitlab-org/-/epics/7881) | TBD | @svedova | Started | Help wanted: FE for 2 Milestones. May need BE |
| 29 | [Improve on and add vulnerability/finding GraphQL endpoints to allow frontend to write better code for existing features](https://gitlab.com/groups/gitlab-org/-/epics/7825) | TBD | @dftian | Not started | Help wanted: BE for <2 Milestones. |
epic