Quarterly, GitLab conducts source code checks for vulnerabilities according to the service risk rating assignment.
By manually and automatically reviewing our source code for security vulnerabilities and best-practices, we can preemptively identify and address risks to our customers, GitLab teammembers, and partners. Code security checks also help us evaluate the consistency of secure coding standards and improve our application security training.
This control applies to all GitLab source code.
SAST and Dependency Scanning are initiated by pipelines for production code. Pipelines are managed by all teams, not a single team.
Non-public information relating to this security control as well as links to the work associated with various phases of project work can be found in the Code Security Check control issue.
Examples of evidence an auditor might request to satisfy this control: