Only ignore `not_affected` CS findings
What does this MR do?
After further discussion with AppSec and Compliance team, there seems to be some disagreement on what should and what should not be ignored to comply with FedRAMP requirements. Only not_affected
status seems to be agreed for now. will_not_fix
and end_of_life
are being debated.
What are the relevant issue numbers?
Does this MR meet the acceptance criteria?
-
Changelog entry added -
Documentation created/updated for GitLab EE, if necessary -
Documentation created/updated for this project, if necessary -
Documentation reviewed by technical writer or follow-up review issue created -
Tests added for this feature/bug -
Job definition updated, if necessary -
Conforms to the code review guidelines -
Conforms to the Go guidelines -
Security reports checked/validated by reviewer