Skip to content

Update compliance framework policy

Aishwarya Subramanian requested to merge update-compliance-framework-policy into master

What does this MR do?

manage_compliance_framework policy checks if the License custom_compliance_frameworks and FF ff_custom_compliance_frameworks is available at the instance level.

Since licenses are applied to groups in gitlab.com, this MR updates the policy to check license and FF at namespace level. For self-managed instances, it will fallback to global check.

Addresses !53182 (comment 505789887)

Screenshots (strongly suggested)

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Aishwarya Subramanian

Merge request reports

Loading