To search repositories and projects, login to gitlab.com.
Suggestions
GitLab Duo Agent PlatformCode Suggestions (AI)CI/CDGitLab on AWSGitLab on Google CloudWhy GitLab?
  • Execution & Workflows
    • CI/CD
    • Source Code Management
    • Agile Delivery
    Security & Governance
    • Application Security Testing
    • Governance & Compliance
    • Supply Chain Security
    Context & AI
    • Agentic Orchestration
    • Context Graph
    • Visibility & Measurement
    Explore the Platform
    Why GitLab

    One platform for speed with control across your software lifecycle.

    Learn more
  • Outcomes
    • DevOps Modernization
    • Security Modernization
    • AI Modernization
    By size
    • Enterprise
    • Small Business
    • Startups
    Industries
    • Financial Services
    • Public Sector
    • Telecommunications
    • Automotive
    • Education
    • Aerospace
    View all Solutions
    GitLab Transcend

    Catch our latest innovations announced at the last Transcend.

    Read the blog
  • Pricing
  • Discover
    • Docs
    • University
    • Demo Series
    • Demo Hub
    • Services
    Connect
    • Blog
    • Community
    • Customers
    • Partners
    • Events
    View all resources
    What’s new in GitLab

    Stay updated with our latest features and improvements.

    Read the latest
    • About
    • Jobs
    • Press
    • Handbook
    • Leadership
    • Investor relations
    • Trust Center
    • AI Transparency Center
    • Newsletter
    • Talk to sales
    • Support portal
    • Customer portal
Request a demoGet free trialSign in
  • English
  • Deutsch
  • Français
  • 日本語
Get free trial
Ship at agent speed. Prove every step. Transcend returns on October 6.Register now
Blog
Daniel Abeles
Daniel Abeles headshot

Daniel Abeles

Recent posts

Security Labs

Critical remote code execution in vm2, a widely used Node.js sandbox library

GitLab's Threat Research Group found a critical sandbox escape in vm2 that runs attacker code using the library's own documented configuration.

Security Labs

Critical remote code execution in Serena, a popular MCP coding agent

GitLab's Threat Research Group found a critical template injection in Serena that runs attacker code the moment a developer opens a repository.

Security Labs

A sandbox is only as closed as what an AI agent can reach

Stuck in an evaluation with no way out, an AI agent escaped in an hour through the one service on its allowlist. Here's the gap that opened.

Security Labs

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

GitLab’s Vulnerability Research team has uncovered a new Python supply chain attack targeting PyPI, deploying the Shai-Hulud worm to steal credentials from CI/CD systems.

Security Labs

GitLab discovers widespread npm supply chain attack

Malware driving attack includes "dead man's switch" that can harm user data.

Stay in the know with GitLab's monthly newsletter

All fields required

Ready to get started?

See what your team could do with a unified DevSecOps Platform

Get free trial

Find out which plan works best for your team

Learn about pricing

Learn about what GitLab can do for your team

Talk to an expert
®

Footer links

Pricing

  • View plans
  • Why Premium?
  • Why Ultimate?

Contact Us

  • Contact sales
  • Support portal
  • Customer portal
  • Status
  • Terms of use
  • Privacy statement

Platform

  • Explore the platform
  • Agentic Orchestration
  • CI/CD
  • Context Graph
  • Why GitLab

Topics

  • CI/CD
  • GitOps
  • DevOps
  • Version Control
  • DevSecOps
  • Cloud Native
  • AI for Coding
  • Agentic AI

Solutions

  • DevOps modernization
  • Security modernization
  • AI modernization
  • Financial services
  • Public sector
  • Telecommunications
  • Automotive
  • Education
  • Aerospace
  • Enterprise
  • Small business
  • Startups
  • GitOps
  • Software composition analysis
  • Value stream management
  • All solutions

Resources

  • Install
  • Quick start guides
  • Docs
  • University
  • Demo Series
  • Demo Hub
  • Services
  • Blog
  • Community
  • Customers
  • Partners
  • Events
  • Newsletter
  • What's new
  • All resources

Company

  • About
  • Jobs
  • Press
  • Handbook
  • Leadership
  • Investor relations
  • Trust Center
  • AI Transparency Center
  • Sustainability
  • Diversity, inclusion and belonging (DIB)
  • Modern Slavery Transparency Statement

Git is a trademark of Software Freedom Conservancy and our use of 'GitLab' is under license

View page sourceEdit this pagePlease contribute

© 2026 GitLab Inc.