How to monitor and respond to issues with SAST Automatic Vulnerability Resolution?
When to use this runbook?
This runbook is intended to be used when there is a service degaradation in relation to the SAST Automatic Vulnerability Resolution feature. Such degradation can be identified by monitoring the following:
- Sidekiq Error Rate (in the Static Analysis group dashboard) with
Vulnerabilities::MarkDroppedAsResolvedWorker
selected. - Sidekiq execution Apdex and Error Ratio panels from the Static Analysis error budget.
SAST Automatic Vulnerability Resolution
The SAST Automatic Vulnerability Resolution feature is built to, as the name implies, automatically resolve vulnerabilities tied to SAST rules that have been disabled or removed.