4 ms·
They have a sast scanner offering..we tried to use it Basic thinks like "ignore this slew of reporting because the build is already deprecated" or "always igno
by HdS84 2y ago
They have a sast scanner offering..we tried to use it
Basic thinks like "ignore this slew of reporting because the build is already deprecated" or "always ignore this error, false positive" are missing. The last few years gitlab only did marketing checklist driven development.
- jamesfinlayson 2y agoYes, I've used it and the behaviour that we saw was it reporting every issue that had been in the repo ever (including in files that had been deleted). Which I suppose you might want, but every other scanning tool I've used chose the sensible default of scan what is there now. Also, as far as I can, the security centre wouldn't let you download a .csv of current security issues in the repo - the UI lets you do a bunch of filtering, but the .csv always gives you everything, including issues that you've closed.
- HdS84 2y agoIt's even worse when you scan your build artifacts, in our case containers. Each build added to the list , with no way to delete all stuff. Filtering and grouping are also missing. We gave up on that and decided to use another tool. My gripe with GL is that all features are like this now. There is no invest into the basic building blocks, just yapping for the next trend. Most customers for GL use it on premise because they want to use it on prem. I would focus on Features that benefit that crowd, but hey I am just an developing not a gilded c suite.