Supply chain attacks aren't new, but that doesn't mean extra vigilance and protection aren't needed. We take a look at how we secure our packages and registries. Read on
We built a program that encourages, recognizes, and awards a shared responsibility for security.
Learn how this group of team members works to preserve and reinforce GitLab values in the Security department and beyond.
We improve consistency across severity ratings and payouts in our bug bounty program with collaboration, iteration, and async communication.
How we responded to a masked variable vulnerability in GitLab Runner version 13.9.0-rc1 and actions users should take.
Learn how to secure your Android application with Static Application Security Testing.
We take a look back at the year in bugs and bounties and celebrate the reporters and contributions that make us more secure.
Security may not be the first thing that comes to mind when thinking of our DevOps platform, but we’re going to make the case it should be. Here’s a look at some of the too-often-overlooked security features in GitLab Ultimate.
We help you get started with securing your Kubernetes cluster using Cilium, a GitLab-managed application.
Faster releases, more open source code, and developers unlikely to have formal security training = at risk software apps. The solution? A security champions program.
From triage to containers and secrets storage, we took a look at the most vulnerable areas across thousands of hosted projects on GitLab.com. Here's what you need to know.
Our AppSec team breaks down what makes a great bug bounty report. That advice comes just in time, as we're having another bug bounty contest.
Keep your DAST job within timeout limits and fine-tune job configurations for better results
Our next release, 13.4, will include narrow breaking changes for our Secure scanning features. Find out how this could affect you and what you need to do.
Our AppSec team built and ran a CTF, and now it's available for you to play at home.
When tasked to compare security tools, it's critical to understand what's a fair benchmark. We take you step by step through WebGoat's lessons and compare them to SAST and DAST results.