[{"data":1,"prerenderedAt":981},["ShallowReactive",2],{"/blog/transcend-dependency-firewall":3,"navigation-en-us":207,"banner-en-us":639,"footer-en-us":649,"blog-post-authors-en-us-Alisa Ho|Amit Shalem":910,"blog-related-posts-en-us-transcend-dependency-firewall":935,"blog-share-wrapper-en-us":961,"next-steps-en-us":971},{"id":4,"title":5,"authors":6,"body":9,"category":188,"date":189,"description":190,"extension":191,"externalUrl":192,"faq":192,"featured":193,"heroImage":194,"meta":195,"navigation":196,"path":197,"seo":198,"slug":200,"stem":201,"tags":202,"template":205,"updatedDate":192,"__hash__":206},"blogPosts/en-us/blog/transcend-dependency-firewall.md","Dependency Firewall: Block risky packages before the build",[7,8],"Alisa Ho","Amit Shalem",{"type":10,"value":11,"toc":179},"minimark",[12,23,26,35,47,52,55,58,92,95,98,105,109,112,115,118,124,128,131,134,137,143,147,150,153,156,162,166],[13,14,15,16,22],"p",{},"Attackers disguise malicious packages as ones you trust. In June 2026, ",[17,18,21],"a",{"href":19,"rel":20},"https://about.gitlab.com/blog/shai-hulud-copycat-campaign-targets-python-developers/",[],"GitLab researchers found five malicious PyPI packages",", four of them typosquats of Flask, Requests, and NumPy, that run at install time and steal CI/CD credentials. Additionally, AI coding agents now add open source dependencies on their own, often unreviewed, so developers don't have oversight into what packages may contaminate your build.",[13,24,25],{},"Once a malicious or vulnerable package enters your build, its code may run with the same access in your CI pipeline, and it can then reach any system your pipelines touch.",[13,27,28,29,34],{},"GitLab ",[17,30,33],{"href":31,"rel":32},"https://about.gitlab.com/dependency-firewall/beta/",[],"Dependency Firewall",", introduced today at Transcend in early access, can block packages that match your policy, including malicious, vulnerable, and non-compliant packages, before they reach your build. Built-in governance stops risk before install, so your team doesn’t have to trace, remove, or rebuild what a policy blocks. Developers and their agents can keep pulling the dependencies they need without waiting on a manual security review, and packages that satisfy your policy requirements become part of your official build.",[36,37,38],"blockquote",{},[13,39,40,41,46],{},"Watch the ",[17,42,45],{"href":43,"rel":44},"https://about.gitlab.com/events/transcend/virtual/",[],"replay of our Transcend event"," to see demos of new platform capabilities and explore what it takes to carry the speed of agentic AI across the full software lifecycle.",[48,49,51],"h2",{"id":50},"block-malicious-packages-without-breaking-your-build","Block malicious packages without breaking your build",[13,53,54],{},"Without a policy at the point of install, a bad package goes into the build first and gets caught later. Software composition analysis (SCA) scans what you've already pulled in, so by the time it flags a malicious package, a high-severity vulnerability, or a license your legal team won't accept, the dependency is installed and may have shipped in an artifact. Tracing where it went, pulling it out, and rebuilding turns a routine pipeline run into unplanned work for your engineering team.",[13,56,57],{},"With Dependency Firewall, you decide what's allowed into your builds before it's installed, by defining policies for:",[59,60,61,74,80,86],"ol",{},[62,63,64,68,69],"li",{},[65,66,67],"strong",{},"Malicious status"," — packages flagged in ",[17,70,73],{"href":71,"rel":72},"https://docs.gitlab.com/user/application_security/gitlab_advisory_database/#gitlab-malware-advisories",[],"GitLab's malware advisory database",[62,75,76,79],{},[65,77,78],{},"Vulnerability severity"," — the severity you set (critical, high, medium, or low) and the number of findings you allow at that level, including zero",[62,81,82,85],{},[65,83,84],{},"License type"," — the licenses you allow or deny, listed by full name, and how to handle packages whose license can't be determined",[62,87,88,91],{},[65,89,90],{},"Package age"," — the minimum age a package must reach before it can enter a build, so a version published minutes ago can't go straight in before anyone has vetted it",[13,93,94],{},"Rolling out enforcement does not have to put delivery at risk. Start in warn mode, where the firewall records what a policy would catch, but lets the build continue. It leaves an audit event, a dashboard entry, and a line in the CI summary, so you can analyze whether or not to block the build.",[13,96,97],{},"Once you trust the policies, switch to block mode, which stops the pipeline on a match and gives the reason. When someone has a real need to get an approved package through, a logged bypass lets a designated user or token proceed, on the record.",[13,99,100],{},[101,102],"img",{"alt":103,"src":104},"Enforce security policies","https://res.cloudinary.com/about-gitlab-com/image/upload/v1791198870/smilnde9xskkyon7rzyn.jpg",[48,106,108],{"id":107},"set-policy-once-or-tailor-it-by-team","Set policy once, or tailor it by team",[13,110,111],{},"A firewall that enforces only at the registry gives everyone the same policy, but that rarely fits how teams actually work. A payments service and an internal prototype carry very different risk, and your policy should treat them differently.",[13,113,114],{},"With Dependency Firewall, you set one policy at the top-level group and every project beneath it inherits the same rules. When a team needs something different, you can set a policy for that group or project.",[13,116,117],{},"You can also enforce policy at the registry, so every pull is checked, not just pulls from a pipeline. Rules live as code in a security policy project, so they are reviewed and changed through a merge request like the rest of your configuration. They inherit from the top-level group down to each project, and where rules overlap the strictest one applies. A critical service can be held above the organization's baseline, and no project drops below it.",[13,119,120],{},[101,121],{"alt":122,"src":123},"New dependency firewall policy","https://res.cloudinary.com/about-gitlab-com/image/upload/v1791198870/aykp66qb64pskauvzbmm.jpg",[48,125,127],{"id":126},"check-a-package-before-you-pull-it-in","Check a package before you pull it in",[13,129,130],{},"A developer, or an agent working on their behalf, usually finds out a package is not allowed only when the pipeline fails. That costs a build cycle and breaks concentration, right when the work is moving.",[13,132,133],{},"You get the answer from GitLab Dependency Firewall before you add a dependency, in the place you already work, allowing  you to pick a package that passes the first time.",[13,135,136],{},"Using GitLab CLI within the terminal or within a script,  a command line check can identify if a package will pass or be blocked by your policy, without requiring developers to open a separate console. It covers common package managers such as npm, pip, Poetry, Maven, Gradle, and Bundler, with more coming soon.",[13,138,139],{},[101,140],{"alt":141,"src":142},"Use command line to identify if a package will pass or be blocked by your policy","https://res.cloudinary.com/about-gitlab-com/image/upload/v1791198870/itqcvrmp8gvw1phihd2l.jpg",[48,144,146],{"id":145},"see-and-prove-every-decision","See and prove every decision",[13,148,149],{},"A security leader has to be able to prove what a control is doing during an audit. A control that blocks quietly, with no record, does not answer the auditor’s question and does not build trust with the teams it governs.",[13,151,152],{},"You get one view of what the firewall has allowed, warned against, and blocked, with an immutable record of each decision you can hand to an auditor.",[13,154,155],{},"A Dependency Firewall dashboard shows activity and outcomes across the projects in scope. Every warn, block, and bypass writes an audit event that records the rule that matched, the policy behind it, and the package involved.",[13,157,158],{},[101,159],{"alt":160,"src":161},"Dependency Firewall dashboard","https://res.cloudinary.com/about-gitlab-com/image/upload/v1791198871/oiieystaargq3ctrqfs1.jpg",[48,163,165],{"id":164},"get-early-access-to-gitlab-dependency-firewall","Get early access to GitLab Dependency Firewall",[13,167,168,169,174,175],{},"You can stop malicious, vulnerable, and non-compliant packages before they reach a build. It is compatible with ",[17,170,173],{"href":171,"rel":172},"https://about.gitlab.com/blog/transcend-artifact-central/",[],"GitLab Artifact Central"," and external registries from Sonatype Nexus Repository and JFrog Artifactory, and does not require standing up a separate tool next to your GitLab deployment. Dependency Firewall is now in early access for GitLab.com and GitLab Self-Managed customers in the Premium or Ultimate tier. ",[17,176,178],{"href":31,"rel":177},[],"Request early access today!",{"title":180,"searchDepth":181,"depth":181,"links":182},"",2,[183,184,185,186,187],{"id":50,"depth":181,"text":51},{"id":107,"depth":181,"text":108},{"id":126,"depth":181,"text":127},{"id":145,"depth":181,"text":146},{"id":164,"depth":181,"text":165},"security","2026-10-06","GitLab Dependency Firewall helps keep malicious and vulnerable packages out of your build automatically, so teams and their agents ship fast with trusted dependencies.","md",null,false,"https://res.cloudinary.com/about-gitlab-com/image/upload/v1791198675/kmajkudog4fj3xc6qfyb.png",{},true,"/en-us/blog/transcend-dependency-firewall",{"config":199,"title":5,"description":190},{"noIndex":193},"transcend-dependency-firewall","en-us/blog/transcend-dependency-firewall",[203,204],"features","product","BlogPost","pTbtlbO8N7cACtknA2ZsGMKOhPTDBfeRzfpWiktmMsc",{"logo":208,"freeTrial":213,"sales":218,"login":223,"items":228,"search":559,"minimal":590,"duo":609,"switchNav":618,"pricingDeployment":629},{"config":209},{"href":210,"dataGaName":211,"dataGaLocation":212},"/","gitlab logo","header",{"text":214,"config":215},"Get free trial",{"href":216,"dataGaName":217,"dataGaLocation":212},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com&glm_content=default-saas-trial/","free trial",{"text":219,"config":220},"Request a demo",{"href":221,"dataGaName":222,"dataGaLocation":212},"/request-a-demo/","sales",{"text":224,"config":225},"Sign in",{"href":226,"dataGaName":227,"dataGaLocation":212},"https://gitlab.com/users/sign_in/","sign in",[229,315,403,408,483,537],{"text":230,"left":196,"config":231,"menu":233},"Platform",{"dataNavLevelOne":232},"platform",{"type":234,"link":235,"columns":239,"feature":304},"lists",{"text":236,"config":237},"Explore the Platform",{"href":238,"dataGaName":232,"dataGaLocation":212},"/platform/",[240,263,286],{"title":241,"items":242},"Execution & Workflows",[243,248,253,258],{"text":244,"config":245},"CI/CD",{"href":246,"dataGaLocation":212,"dataGaName":247},"/solutions/continuous-integration/","ci/cd",{"text":249,"config":250},"Source Code Management",{"href":251,"dataGaLocation":212,"dataGaName":252},"/solutions/source-code-management/","source code management",{"text":254,"config":255},"Agile Delivery",{"href":256,"dataGaLocation":212,"dataGaName":257},"/solutions/agile-delivery/","agile delivery",{"text":259,"config":260},"Artifact Management",{"href":261,"dataGaLocation":212,"dataGaName":262},"/artifact-central/","artifact management",{"title":264,"items":265},"Security & Governance",[266,271,276,281],{"text":267,"config":268},"Application Security Testing",{"href":269,"dataGaLocation":212,"dataGaName":270},"/solutions/application-security-testing/","application security testing",{"text":272,"config":273},"Governance & Compliance",{"href":274,"dataGaLocation":212,"dataGaName":275},"/solutions/software-compliance/","governance and compliance",{"text":277,"config":278},"Secrets Management",{"href":279,"dataGaLocation":212,"dataGaName":280},"/gitlab-secrets-manager/","secrets management",{"text":282,"config":283},"Supply Chain Security",{"href":284,"dataGaLocation":212,"dataGaName":285},"/solutions/supply-chain/","supply chain security",{"title":287,"items":288},"Context & AI",[289,294,299],{"text":290,"config":291},"Agentic Orchestration",{"href":292,"dataGaLocation":212,"dataGaName":293},"/gitlab-duo-agent-platform/","agentic orchestration",{"text":295,"config":296},"Context Graph",{"href":297,"dataGaLocation":212,"dataGaName":298},"/gitlab-orbit/","context graph",{"text":300,"config":301},"Visibility & Measurement",{"href":302,"dataGaLocation":212,"dataGaName":303},"/solutions/visibility-measurement/","visibility and measurement",{"config":305,"title":308,"text":309,"link":310},{"background":306,"textColor":307},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1790185102/o7dn32anqcb6z8dgd3as.jpg')","#000","Why GitLab","One platform for speed with control across your software lifecycle.",{"text":311,"config":312},"Learn more",{"href":313,"dataGaName":314,"dataGaLocation":212},"/why-gitlab/","why gitlab",{"text":316,"left":196,"config":317,"menu":319},"Solutions",{"dataNavLevelOne":318},"solutions",{"type":234,"link":320,"columns":324,"feature":394},{"text":321,"config":322},"View all Solutions",{"href":323,"dataGaName":318,"dataGaLocation":212},"/solutions/",[325,343,361],{"title":326,"items":327},"Outcomes",[328,333,338],{"text":329,"config":330},"DevOps Modernization",{"href":331,"dataGaLocation":212,"dataGaName":332},"/assessments/devops-modernization-assessment/","devops modernization",{"text":334,"config":335},"Security Modernization",{"href":336,"dataGaLocation":212,"dataGaName":337},"/assessments/security-modernization-assessment/","security modernization",{"text":339,"config":340},"AI Modernization",{"href":341,"dataGaLocation":212,"dataGaName":342},"/assessments/ai-modernization-assessment/","ai modernization",{"title":344,"items":345},"By size",[346,351,356],{"text":347,"config":348},"Enterprise",{"href":349,"dataGaLocation":212,"dataGaName":350},"/enterprise/","enterprise",{"text":352,"config":353},"Small Business",{"href":354,"dataGaLocation":212,"dataGaName":355},"/small-business/","small business",{"text":357,"config":358},"Startups",{"href":359,"dataGaLocation":212,"dataGaName":360},"/solutions/startups/","startups",{"title":362,"items":363},"Industries",[364,369,374,379,384,389],{"text":365,"config":366},"Financial Services",{"href":367,"dataGaLocation":212,"dataGaName":368},"/solutions/finance/","financial services",{"text":370,"config":371},"Public Sector",{"href":372,"dataGaLocation":212,"dataGaName":373},"/solutions/public-sector/","public sector",{"text":375,"config":376},"Telecommunications",{"href":377,"dataGaLocation":212,"dataGaName":378},"/solutions/telecommunications/","telecommunications",{"text":380,"config":381},"Automotive",{"href":382,"dataGaLocation":212,"dataGaName":383},"/solutions/automotive/","automotive",{"text":385,"config":386},"Education",{"href":387,"dataGaLocation":212,"dataGaName":388},"/solutions/education/","education",{"text":390,"config":391},"Aerospace",{"href":392,"dataGaLocation":212,"dataGaName":393},"/solutions/aerospace/","aerospace",{"config":395,"title":396,"text":397,"link":398},{"background":306,"textColor":307},"GitLab Security Standard","Learn how to harden your software factory and let AI agents earn autonomy, without trading away security.",{"text":399,"config":400},"Explore the standard",{"href":401,"dataGaName":402,"dataGaLocation":212},"/gitlab-security-standard/","gitlab security standard",{"text":404,"config":405},"Pricing",{"href":406,"dataGaName":407,"dataGaLocation":212,"dataNavLevelOne":407},"/pricing/","pricing",{"text":409,"config":410,"menu":412},"Resources",{"dataNavLevelOne":411},"resources",{"type":234,"link":413,"columns":417,"feature":474},{"text":414,"config":415},"View all resources",{"href":416,"dataGaName":411,"dataGaLocation":212},"/resources/",[418,446],{"title":419,"items":420},"Discover",[421,426,431,436,441],{"text":422,"config":423},"Docs",{"href":424,"dataGaName":425,"dataGaLocation":212},"https://docs.gitlab.com/","docs",{"text":427,"config":428},"University",{"href":429,"dataGaName":430,"dataGaLocation":212},"https://university.gitlab.com/","university",{"text":432,"config":433},"Demo Series",{"href":434,"dataGaName":435,"dataGaLocation":212},"/gitlab-technical-demo-series/","demo series",{"text":437,"config":438},"Demo Hub",{"href":439,"dataGaName":440,"dataGaLocation":212},"/demo-hub/","demo hub",{"text":442,"config":443},"Services",{"href":444,"dataGaName":445,"dataGaLocation":212},"/services/","services",{"title":447,"items":448},"Connect",[449,454,459,464,469],{"text":450,"config":451},"Blog",{"href":452,"dataGaName":453,"dataGaLocation":212},"/blog/","blog",{"text":455,"config":456},"Community",{"href":457,"dataGaName":458,"dataGaLocation":212},"/community/","community",{"text":460,"config":461},"Customers",{"href":462,"dataGaName":463,"dataGaLocation":212},"/customers/","customers",{"text":465,"config":466},"Partners",{"href":467,"dataGaName":468,"dataGaLocation":212},"/partners/","partners",{"text":470,"config":471},"Events",{"href":472,"dataGaName":473,"dataGaLocation":212},"/events/","events",{"config":475,"title":476,"text":477,"link":478},{"background":306,"textColor":307},"What’s new in GitLab","Stay updated with our latest features and improvements.",{"text":479,"config":480},"Read the latest",{"href":481,"dataGaName":482,"dataGaLocation":212},"/whats-new/","whats new",{"text":484,"config":485,"menu":487},"Company",{"dataNavLevelOne":486},"company",{"type":234,"columns":488},[489],{"items":490},[491,496,502,507,512,517,522,527,532],{"text":492,"config":493},"About",{"href":494,"dataGaName":495,"dataGaLocation":212},"/company/","about",{"text":497,"config":498,"footerGa":501},"Jobs",{"href":499,"dataGaName":500,"dataGaLocation":212},"/jobs/","jobs",{"dataGaName":500},{"text":503,"config":504},"Press",{"href":505,"dataGaName":506,"dataGaLocation":212},"/press/","press",{"text":508,"config":509},"Handbook",{"href":510,"dataGaName":511,"dataGaLocation":212},"https://handbook.gitlab.com/","handbook",{"text":513,"config":514},"Leadership",{"href":515,"dataGaName":516,"dataGaLocation":212},"/company/team/e-group/","leadership",{"text":518,"config":519},"Investor relations",{"href":520,"dataGaName":521,"dataGaLocation":212},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":523,"config":524},"Trust Center",{"href":525,"dataGaName":526,"dataGaLocation":212},"/security/","trust center",{"text":528,"config":529},"AI Transparency Center",{"href":530,"dataGaName":531,"dataGaLocation":212},"/ai-transparency-center/","ai transparency center",{"text":533,"config":534},"Newsletter",{"href":535,"dataGaName":536,"dataGaLocation":212},"/company/contact/#contact-forms","newsletter",{"text":538,"config":539,"menu":540},"Contact us",{"dataNavLevelOne":486},{"type":234,"columns":541},[542],{"items":543},[544,549,554],{"text":545,"config":546},"Talk to sales",{"href":547,"dataGaName":548,"dataGaLocation":212},"/sales/","talk to sales",{"text":550,"config":551},"Support portal",{"href":552,"dataGaName":553,"dataGaLocation":212},"https://support.gitlab.com/hc/en-us","support portal",{"text":555,"config":556},"Customer portal",{"href":557,"dataGaName":558,"dataGaLocation":212},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":560,"login":561,"suggestions":568},"Close",{"text":562,"link":563},"To search repositories and projects, login to",{"text":564,"config":565},"gitlab.com",{"href":226,"dataGaName":566,"dataGaLocation":567},"search login","search",{"text":569,"default":570},"Suggestions",[571,574,577,579,583,587],{"text":572,"config":573},"GitLab Duo Agent Platform",{"href":292,"dataGaName":572,"dataGaLocation":567},{"text":575,"config":576},"Code Suggestions (AI)",{"href":292,"dataGaName":575,"dataGaLocation":567},{"text":244,"config":578},{"href":246,"dataGaName":244,"dataGaLocation":567},{"text":580,"config":581},"GitLab on AWS",{"href":582,"dataGaName":580,"dataGaLocation":567},"/partners/technology-partners/aws/",{"text":584,"config":585},"GitLab on Google Cloud",{"href":586,"dataGaName":584,"dataGaLocation":567},"/partners/technology-partners/google-cloud-platform/",{"text":588,"config":589},"Why GitLab?",{"href":313,"dataGaName":588,"dataGaLocation":567},{"freeTrial":591,"mobileIcon":596,"desktopIcon":601,"secondaryButton":604},{"text":592,"config":593},"Start free trial",{"href":594,"dataGaName":217,"dataGaLocation":595},"https://gitlab.com/-/trials/new/","nav",{"altText":597,"config":598},"Gitlab Icon",{"src":599,"dataGaName":600,"dataGaLocation":595},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":597,"config":602},{"src":603,"dataGaName":600,"dataGaLocation":595},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":605,"config":606},"Get Started",{"href":607,"dataGaName":608,"dataGaLocation":595},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/get-started/","get started",{"freeTrial":610,"mobileIcon":614,"desktopIcon":616},{"text":611,"config":612},"Learn more about GitLab Duo",{"href":292,"dataGaName":613,"dataGaLocation":595},"gitlab duo",{"altText":597,"config":615},{"src":599,"dataGaName":600,"dataGaLocation":595},{"altText":597,"config":617},{"src":603,"dataGaName":600,"dataGaLocation":595},{"button":619,"mobileIcon":624,"desktopIcon":626},{"text":620,"config":621},"/switch",{"href":622,"dataGaName":623,"dataGaLocation":595},"#contact","switch",{"altText":597,"config":625},{"src":599,"dataGaName":600,"dataGaLocation":595},{"altText":597,"config":627},{"src":628,"dataGaName":600,"dataGaLocation":595},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":630,"mobileIcon":635,"desktopIcon":637},{"text":631,"config":632},"Back to pricing",{"href":406,"dataGaName":633,"dataGaLocation":595,"icon":634},"back to pricing","GoBack",{"altText":597,"config":636},{"src":599,"dataGaName":600,"dataGaLocation":595},{"altText":597,"config":638},{"src":603,"dataGaName":600,"dataGaLocation":595},{"title":640,"button":641,"config":647},"Ship at agent speed. Prove every step. Transcend returns on October 6.",{"text":642,"config":643},"Register now",{"href":644,"dataGaName":645,"dataGaLocation":646},"/events/transcend/virtual/#register","transcend-october-2026-banner","global-banner",{"layout":648,"disabled":193},"release",{"data":650},{"text":651,"source":652,"edit":658,"contribute":663,"config":668,"items":673,"minimal":899},"Git is a trademark of Software Freedom Conservancy and our use of 'GitLab' is under license",{"text":653,"config":654},"View page source",{"href":655,"dataGaName":656,"dataGaLocation":657},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":659,"config":660},"Edit this page",{"href":661,"dataGaName":662,"dataGaLocation":657},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":664,"config":665},"Please contribute",{"href":666,"dataGaName":667,"dataGaLocation":657},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":669,"facebook":670,"youtube":671,"linkedin":672},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[674,721,779,826,867],{"title":404,"links":675,"subMenu":690},[676,680,685],{"text":677,"config":678},"View plans",{"href":406,"dataGaName":679,"dataGaLocation":657},"view plans",{"text":681,"config":682},"Why Premium?",{"href":683,"dataGaName":684,"dataGaLocation":657},"/pricing/premium/","why premium",{"text":686,"config":687},"Why Ultimate?",{"href":688,"dataGaName":689,"dataGaLocation":657},"/pricing/ultimate/","why ultimate",[691],{"title":692,"links":693},"Contact Us",[694,697,699,701,706,711,716],{"text":695,"config":696},"Contact sales",{"href":547,"dataGaName":222,"dataGaLocation":657},{"text":550,"config":698},{"href":552,"dataGaName":553,"dataGaLocation":657},{"text":555,"config":700},{"href":557,"dataGaName":558,"dataGaLocation":657},{"text":702,"config":703},"Status",{"href":704,"dataGaName":705,"dataGaLocation":657},"https://status.gitlab.com/","status",{"text":707,"config":708},"Terms of use",{"href":709,"dataGaName":710,"dataGaLocation":657},"/terms/","terms of use",{"text":712,"config":713},"Privacy statement",{"href":714,"dataGaName":715,"dataGaLocation":657},"/privacy/","privacy statement",{"text":717,"config":718},"Cookie preferences",{"dataGaName":719,"dataGaLocation":657,"id":720,"isOneTrustButton":196},"cookie preferences","ot-sdk-btn",{"title":230,"links":722,"subMenu":736},[723,726,728,730,732,734],{"text":724,"config":725},"Explore the platform",{"href":238,"dataGaName":232,"dataGaLocation":657},{"text":290,"config":727},{"href":292,"dataGaName":293,"dataGaLocation":657},{"text":244,"config":729},{"href":246,"dataGaName":247,"dataGaLocation":657},{"text":295,"config":731},{"href":297,"dataGaName":298,"dataGaLocation":657},{"text":277,"config":733},{"href":279,"dataGaName":280,"dataGaLocation":657},{"text":308,"config":735},{"href":313,"dataGaName":314,"dataGaLocation":657},[737],{"title":738,"links":739},"Topics",[740,744,749,754,759,764,769,774],{"text":244,"config":741},{"href":742,"dataGaName":743,"dataGaLocation":657},"/topics/ci-cd/","cicd",{"text":745,"config":746},"GitOps",{"href":747,"dataGaName":748,"dataGaLocation":657},"/topics/gitops/","gitops",{"text":750,"config":751},"DevOps",{"href":752,"dataGaName":753,"dataGaLocation":657},"/topics/devops/","devops",{"text":755,"config":756},"Version Control",{"href":757,"dataGaName":758,"dataGaLocation":657},"/topics/version-control/","version control",{"text":760,"config":761},"DevSecOps",{"href":762,"dataGaName":763,"dataGaLocation":657},"/topics/devsecops/","devsecops",{"text":765,"config":766},"Cloud Native",{"href":767,"dataGaName":768,"dataGaLocation":657},"/topics/cloud-native/","cloud native",{"text":770,"config":771},"AI for Coding",{"href":772,"dataGaName":773,"dataGaLocation":657},"/topics/devops/ai-for-coding/","ai for coding",{"text":775,"config":776},"Agentic AI",{"href":777,"dataGaName":778,"dataGaLocation":657},"/topics/agentic-ai/","agentic ai",{"title":316,"links":780},[781,784,787,790,793,796,798,800,802,804,806,809,811,814,818,822],{"text":782,"config":783},"DevOps modernization",{"href":331,"dataGaName":332,"dataGaLocation":657},{"text":785,"config":786},"Security modernization",{"href":336,"dataGaName":337,"dataGaLocation":657},{"text":788,"config":789},"AI modernization",{"href":341,"dataGaName":342,"dataGaLocation":657},{"text":791,"config":792},"Financial services",{"href":367,"dataGaName":368,"dataGaLocation":657},{"text":794,"config":795},"Public sector",{"href":372,"dataGaName":373,"dataGaLocation":657},{"text":375,"config":797},{"href":377,"dataGaName":378,"dataGaLocation":657},{"text":380,"config":799},{"href":382,"dataGaName":383,"dataGaLocation":657},{"text":385,"config":801},{"href":387,"dataGaName":388,"dataGaLocation":657},{"text":390,"config":803},{"href":392,"dataGaName":393,"dataGaLocation":657},{"text":347,"config":805},{"href":349,"dataGaName":350,"dataGaLocation":657},{"text":807,"config":808},"Small business",{"href":354,"dataGaName":355,"dataGaLocation":657},{"text":357,"config":810},{"href":359,"dataGaName":360,"dataGaLocation":657},{"text":745,"config":812},{"href":813,"dataGaName":748,"dataGaLocation":657},"/solutions/gitops/",{"text":815,"config":816},"Software composition analysis",{"href":284,"dataGaName":817,"dataGaLocation":657},"software composition analysis",{"text":819,"config":820},"Value stream management",{"href":302,"dataGaName":821,"dataGaLocation":657},"value stream management",{"text":823,"config":824},"All solutions",{"href":323,"dataGaName":825,"dataGaLocation":657},"all solutions",{"title":409,"links":827},[828,833,838,840,842,844,846,848,850,852,854,856,858,860,863],{"text":829,"config":830},"Install",{"href":831,"dataGaName":832,"dataGaLocation":657},"/install/","install",{"text":834,"config":835},"Quick start guides",{"href":836,"dataGaName":837,"dataGaLocation":657},"/get-started/","quick setup checklists",{"text":422,"config":839},{"href":424,"dataGaName":425,"dataGaLocation":657},{"text":427,"config":841},{"href":429,"dataGaName":430,"dataGaLocation":657},{"text":432,"config":843},{"href":434,"dataGaName":435,"dataGaLocation":657},{"text":437,"config":845},{"href":439,"dataGaName":440,"dataGaLocation":657},{"text":442,"config":847},{"href":444,"dataGaName":445,"dataGaLocation":657},{"text":450,"config":849},{"href":452,"dataGaName":453,"dataGaLocation":657},{"text":455,"config":851},{"href":457,"dataGaName":458,"dataGaLocation":657},{"text":460,"config":853},{"href":462,"dataGaName":463,"dataGaLocation":657},{"text":465,"config":855},{"href":467,"dataGaName":468,"dataGaLocation":657},{"text":470,"config":857},{"href":472,"dataGaName":473,"dataGaLocation":657},{"text":533,"config":859},{"href":535,"dataGaName":536,"dataGaLocation":657},{"text":861,"config":862},"What's new",{"href":481,"dataGaName":482,"dataGaLocation":657},{"text":864,"config":865},"All resources",{"href":416,"dataGaName":866,"dataGaLocation":657},"all resources",{"title":484,"links":868},[869,871,873,875,877,879,881,883,885,889,894],{"text":492,"config":870},{"href":494,"dataGaName":486,"dataGaLocation":657},{"text":497,"config":872},{"href":499,"dataGaName":500,"dataGaLocation":657},{"text":503,"config":874},{"href":505,"dataGaName":506,"dataGaLocation":657},{"text":508,"config":876},{"href":510,"dataGaName":511,"dataGaLocation":657},{"text":513,"config":878},{"href":515,"dataGaName":516,"dataGaLocation":657},{"text":518,"config":880},{"href":520,"dataGaName":521,"dataGaLocation":657},{"text":523,"config":882},{"href":525,"dataGaName":526,"dataGaLocation":657},{"text":528,"config":884},{"href":530,"dataGaName":531,"dataGaLocation":657},{"text":886,"config":887},"Sustainability",{"href":888,"dataGaName":886,"dataGaLocation":657},"/sustainability/",{"text":890,"config":891},"Diversity, inclusion and belonging (DIB)",{"href":892,"dataGaName":893,"dataGaLocation":657},"/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":895,"config":896},"Modern Slavery Transparency Statement",{"href":897,"dataGaName":898,"dataGaLocation":657},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":900},[901,904,907],{"text":902,"config":903},"Terms",{"href":709,"dataGaName":710,"dataGaLocation":657},{"text":905,"config":906},"Cookies",{"dataGaName":719,"dataGaLocation":657,"id":720,"isOneTrustButton":196},{"text":908,"config":909},"Privacy",{"href":714,"dataGaName":715,"dataGaLocation":657},[911,924],{"id":912,"title":7,"body":192,"config":913,"content":915,"description":192,"extension":918,"meta":919,"navigation":196,"path":920,"seo":921,"stem":922,"__hash__":923},"blogAuthors/en-us/blog/authors/alisa-ho.yml",{"template":914},"BlogAuthor",{"name":7,"config":916},{"headshot":917},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1771440109/xcnydlisb91u4qiwdyw2.jpg","yml",{},"/en-us/blog/authors/alisa-ho",{},"en-us/blog/authors/alisa-ho","WU4QiU5Np9PQ8aLtvZXnH41_rF4JeUvaD9lOvDqkzYw",{"id":925,"title":8,"body":192,"config":926,"content":927,"description":192,"extension":918,"meta":930,"navigation":196,"path":931,"seo":932,"stem":933,"__hash__":934},"blogAuthors/en-us/blog/authors/amit-shalem.yml",{"template":914},{"name":8,"config":928},{"headshot":929},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1789051782/t66kjqncbzsznqsokogo.png",{},"/en-us/blog/authors/amit-shalem",{},"en-us/blog/authors/amit-shalem","myYkfCRRxt-YcE_B3aEI5IBr8ZsVXHZ7UdbKwEabo4I",[936,944,953],{"title":937,"description":938,"heroImage":939,"category":188,"date":940,"authors":941,"slug":943,"externalUrl":192},"Securing the software factory at machine speed","The foundation for agentic software development must evolve with AI models, continuously shortening the path from detection to verified remediation.","https://res.cloudinary.com/about-gitlab-com/image/upload/v1759320418/xjmqcozxzt4frx0hori3.png","2026-09-18",[942],"Chaim Mazal","securing-the-software-factory-at-machine-speed",{"title":945,"description":946,"heroImage":947,"category":188,"date":948,"authors":949,"slug":952,"externalUrl":192},"When to use SAST versus an LLM security scanner","AI-based review and SAST catch different classes of bugs and both have benefits. Here's how to decide which one runs where, and when your team needs both. ","https://res.cloudinary.com/about-gitlab-com/image/upload/v1756989645/fojzxakmfdea6jfqjkrl.png","2026-09-16",[950,951],"Meir Benayoun","Chris Widstrom","sast-vs-llm-security-scanner",{"title":954,"description":955,"heroImage":956,"category":188,"date":957,"authors":958,"slug":960,"externalUrl":192},"GitLab Dedicated: Compliance for a new regulatory era","Streamline compliance with GitLab Dedicated. Gain isolation, control, and audit readiness for DORA, NIS2, and GDPR in a single-tenant SaaS environment.","https://res.cloudinary.com/about-gitlab-com/image/upload/v1756122536/akivvcnafog9c4dhhzkp.png","2026-09-14",[959],"Aathira Nair","gitlab-dedicated-compliance",{"header":962,"text":963,"button":967,"disclaimer":970},"Start your free\n\n30-day GitLab trial\n",[964,965,966],"GitLab Duo Agent Platform access","Try our most advanced features","Automate complex tasks with AI",{"text":214,"config":968},{"href":969,"dataGaName":217,"dataGaLocation":453},"https://gitlab.com/-/trials/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/blog/","No credit card required.",{"header":972,"blurb":973,"button":974,"secondaryButton":979},"Start building faster today","See what your team can do with the intelligent orchestration platform for DevSecOps.\n",{"text":975,"config":976},"Get your free trial",{"href":977,"dataGaName":217,"dataGaLocation":978},"https://gitlab.com/-/trial_registrations/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/","feature",{"text":695,"config":980},{"href":547,"dataGaName":222,"dataGaLocation":978},1791355833666]