Ask GitLab Security: Alexander Dietrich
…to “cloud native,” with me changing focus from writing software to making sure that software is written and operated securely. Being able to apply my general security-mindedness at work was a…
Security scans generate hundreds of findings. Security teams manually triage each one while developers wait for approval to deploy. Most findings are false positives or low-risk issues, but identifying the real threats requires expertise and time. AI can prioritize findings by actual exploitability and auto-remediate common vulnerabilities, allowing security teams to focus on the threats that matter.
10 AI prompts to speed your team’s software deliveryCode changes faster than documentation. Onboarding new developers takes weeks because docs are outdated or missing. Teams know documentation is important, but it always gets deferred when deadlines approach. Automating documentation generation and updates as part of your standard workflow ensures docs stay current without adding manual work.
10 AI prompts to speed your team’s software delivery…to “cloud native,” with me changing focus from writing software to making sure that software is written and operated securely. Being able to apply my general security-mindedness at work was a…
…Expanding our security certification portfolio Learn how the Security Compliance team uses the Agile planning and security features in the GitLab DevSecOps Platform to manage the certification process. Madeline Lake agile security…
…Heather Simpson careers inside GitLab security security What’s it like working to secure one of the most transparent organizations in the world? To be a security practitioner in a highly iterative…
…Using CI/CD rules, security and quality assurance teams can dynamically run extra checks on changes introduced when certain factors are introduced. For example, malware scans can be added when new file…
…Scanner enforcement holds a change at the pipeline level until it clears the security and quality checks your organization requires. We recommend creating an organization-wide AI governance policy rather than leaving…
…Taking each day as an opportunity to learn something new is also super important as one needs to keep up with changing technological trends in security. Liz Coleman - Sr. Security Assurance Engineer…
…We're thrilled to recognize @taraszelyk , whose back-to-back information disclosure submissions led to a lot of positive security changes within GitLab. Thanks, Taras! We will be getting in touch with…
…For any GitLab Duo generated code, changes are managed via merge requests which trigger your CI pipeline (including any security and code quality scanning you have configured). This ensures any governance rules…
…What must change is how carefully we draw those lists to minimize reachability. Find more articles from the Threat Research team on our Security Labs site . More to explore Security Labs Shai…
…When an agent can run tests, modify configurations, and take multi-step actions across your software delivery lifecycle without a human reviewing each step, the security requirements change significantly. The questions that…