7 steps to enhance application security without slowing developer velocity

Organizations are feeling an increased sense of urgency to ensure the security of their built applications by putting in place cybersecurity protocols. However, as they enable security analyzers on source code and related assets, they find that the amount of data they are getting in terms of potential vulnerabilities is…

Continue Reading7 steps to enhance application security without slowing developer velocity

3 tips to improve your security risk management program

Risk management is typically viewed as a check-the-box compliance activity. It can also be seen as a blocker. Effective risk management programs provide their company’s decision-makers with relevant, reliable, and usable information to support the achievement of objectives and mitigation of risks. GitLab’s Security Operational Risk Management (StORM) program identifies,…

Continue Reading3 tips to improve your security risk management program

GitLab Duo Chat 101: Get more done on GitLab with our AI assistant

GitLab Duo Chat became generally available in GitLab 16.11 and its power as a personal assistant can not be overstated. On a DevSecOps platform, more has to happen than just generating code; planning, discussions, security, compliance, and technical reviews are all critical to developing secure software faster. Issues, epics, merge…

Continue ReadingGitLab Duo Chat 101: Get more done on GitLab with our AI assistant

Developing GitLab Duo: Secure and thoroughly test AI-generated code

Generative AI marks a monumental shift in the software development industry, making it easier to develop, secure, and operate software. Our new blog series, written by our product and engineering teams, gives you an inside look at how we create, test, and deploy the AI features you need integrated throughout…

Continue ReadingDeveloping GitLab Duo: Secure and thoroughly test AI-generated code

GitLab extends Omnibus package signing key expiration to 2025

Note: The Omnibus package signing key is separate from the Access Token Expiry affecting users of GitLab 16.0 and above. For more information about Access Token Expiry, please see our blog on the topic. GitLab uses a GNU Privacy Guard (GPG) key to sign all Omnibus packages created within the…

Continue ReadingGitLab extends Omnibus package signing key expiration to 2025

Developing GitLab Duo series

Generative AI marks a monumental shift in the software development industry, making it easier to develop, secure, and operate software. Our blog series, written by our product and engineering teams, gives you an inside look at how we create, test, and deploy the AI features you need integrated throughout the…

Continue ReadingDeveloping GitLab Duo series

Inside look: How GitLab’s Test Platform team validates AI features

AI is increasingly becoming a centerpiece of software development - many companies are integrating it throughout their DevSecOps workflows to improve productivity and increase efficiency. Because of this now-critical role, AI features should be tested and analyzed on an ongoing basis. In this article, we take you behind the scenes…

Continue ReadingInside look: How GitLab’s Test Platform team validates AI features

Secure by Design principles meet DevSecOps innovation in GitLab 17

Secure by Design just turned one! Introduced by the Cybersecurity and Infrastructure Security Agency (CISA) a little over a year ago, Secure by Design principles serve as a directive for technology providers to embed security at the heart of their products from the outset of development. This approach is the…

Continue ReadingSecure by Design principles meet DevSecOps innovation in GitLab 17