Detection parity with SD Default rules [public]
Problem to solve
The secrets that DAST detects are not the same secrets that our secret detection analyzer detects.
As a security analyst, I want the same secrets to be detected by both the SD and DAST analyzers, so that I can reduce false positives and false negatives, and ensure my organization is well protected from secret leaks.
Proposal
Once groupsecret detection completes their work in Decouple Secret Detection rules from scanning l... (gitlab-org#14534 - closed), the DAST team should ingest these detections automatically. When SD detections are updated, the updates should carry over to secret-related detections for DAST.
Edited by 🤖 GitLab Bot 🤖