Produce json security report in production
Problem
API Fuzzer can generate security vulnerability reports, but it's not enabled in production.
Second half to #224726 (closed)
This work must be done after the frontend work has been completed.
Proposal
Enable security report generation in production.
-
The worker-entry
is updated to generate report -
The gitlabpoc is modified to support the new report method -
Update template -
Update documentation - Address #285474 (closed)
- User documentation
-
Add tests -
Verify report generated when no faults found
On completion of testing, produce a json report suitable for the security dashboard. The fuzzer results will show up on the security dashboard, and not as junit results.
/cc @sethgitlab @stkerr
The following page may contain information related to upcoming products, features and functionality. It is important to note that the information presented is for informational purposes only, so please do not rely on the information for purchasing or planning purposes. Just like with all projects, the items mentioned on the page are subject to change or delay, and the development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.