7 steps to enhance application security without slowing developer velocity

Organizations are feeling an increased sense of urgency to ensure the security of their built applications by putting in place cybersecurity protocols. However, as they enable security analyzers on source code and related assets, they find that the amount of data they are getting in terms of potential vulnerabilities is…

Continue Reading7 steps to enhance application security without slowing developer velocity

GitLab native secrets manager to give software supply chain security a boost

In a constantly evolving digital world, keeping the software supply chain and sensitive information secure is a priority for organizations of all sizes. To reduce the complexity associated with managing multiple infrastructure tools, GitLab plans to release a native secrets manager later this year that will enable users to manage…

Continue ReadingGitLab native secrets manager to give software supply chain security a boost

Developing GitLab Duo: AI Impact analytics dashboard measures the ROI of AI

Generative AI marks a monumental shift in the software development industry, making it easier to develop, secure, and operate software. Our new blog series, written by our product and engineering teams, gives you an inside look at how we create, test, and deploy the AI features you need integrated throughout…

Continue ReadingDeveloping GitLab Duo: AI Impact analytics dashboard measures the ROI of AI

Rate limitations announced for Projects, Groups, and Users APIs

In recent months, we have observed that the frequency and intensity of requests made by users to the Projects, Groups, and Users APIs have increased significantly. This has resulted in an increased load on our servers, which has impacted the performance and stability of our platform for all users. To…

Continue ReadingRate limitations announced for Projects, Groups, and Users APIs

Secure by Design principles meet DevSecOps innovation in GitLab 17

Secure by Design just turned one! Introduced by the Cybersecurity and Infrastructure Security Agency (CISA) a little over a year ago, Secure by Design principles serve as a directive for technology providers to embed security at the heart of their products from the outset of development. This approach is the…

Continue ReadingSecure by Design principles meet DevSecOps innovation in GitLab 17

Inside look: How GitLab’s Test Platform team validates AI features

AI is increasingly becoming a centerpiece of software development - many companies are integrating it throughout their DevSecOps workflows to improve productivity and increase efficiency. Because of this now-critical role, AI features should be tested and analyzed on an ongoing basis. In this article, we take you behind the scenes…

Continue ReadingInside look: How GitLab’s Test Platform team validates AI features

Developing GitLab Duo series

Generative AI marks a monumental shift in the software development industry, making it easier to develop, secure, and operate software. Our blog series, written by our product and engineering teams, gives you an inside look at how we create, test, and deploy the AI features you need integrated throughout the…

Continue ReadingDeveloping GitLab Duo series

Developing GitLab Duo: Secure and thoroughly test AI-generated code

Generative AI marks a monumental shift in the software development industry, making it easier to develop, secure, and operate software. Our new blog series, written by our product and engineering teams, gives you an inside look at how we create, test, and deploy the AI features you need integrated throughout…

Continue ReadingDeveloping GitLab Duo: Secure and thoroughly test AI-generated code

GitLab extends Omnibus package signing key expiration to 2025

Note: The Omnibus package signing key is separate from the Access Token Expiry affecting users of GitLab 16.0 and above. For more information about Access Token Expiry, please see our blog on the topic. GitLab uses a GNU Privacy Guard (GPG) key to sign all Omnibus packages created within the…

Continue ReadingGitLab extends Omnibus package signing key expiration to 2025