Announcing The GitLab Issue Board
…planning, people, process, and policy) together. They all boil up to the same key ideas. Policies and plans should be centralized. Ownership must be clear. Finally, a change in plans needs to…
…planning, people, process, and policy) together. They all boil up to the same key ideas. Policies and plans should be centralized. Ownership must be clear. Finally, a change in plans needs to…
…What is the most significant piece of security advice you could provide to the companies you hack? Have a clear policy for the reporting of security vulnerabilities. Whether it’s a vulnerability…
…This change can affect open source organizations that publish their images on Docker Hub, as well as consumers of these container images, used in CI/CD pipelines, Kubernetes cluster deployments, or docker…
…We want to do this because we want to minimize as much as possible the detrimental impact doing changes can have on pipeline performance. Execute fewer jobs and pipelines Let's look…
…Review Apps Wouldn’t it be great if you could effortlessly enable all stakeholders to review the application changes BEFORE they are merged to the main branch? Instead of orchestrating and putting…
…Enhanced security Eliminates the need for storing cluster credentials in GitLab Provides secure, bidirectional communication between GitLab and your clusters Supports fine-grained access control and authorization policies Enables secure GitOps workflows…
…Command line junkies practically have their own religion around workflow and we’re introducing a change to that workflow. Yes, it is a minor change, but it already concerns me. Truthfully, because…
…Customers can opt out of these changes, disabling the GitLab active checks and re-enabling the ZAP alerts by adding the CI/CD variable DAST_FF_BROWSER_BASED_ACTIVE_ATTACK: "false" . What…
…This allows us to test more changes, more accurately, in staging before rolling them out to production. Previously the team was maintaining a limited scaled-down staging environment and many changes were…
…Creating a forecast on possible scenarios to defend is hard, so let us change roles from the defender to the attacker for a moment. Which security vulnerabilities are out there to exploit…