
3/29/2022 · Sandra Gittlen
What this post added
This post details how GitLab addresses the specific practices within the NIST SSDF: Prepare the organization (policy management, role-based permissions, security dashboards, zero-trust), Protect software (SCM, commit signatures, code reviews, hardened containers, MR approvals, SBOM, offline scanning), Produce well-secured software (credential management, vulnerability reports, integrated security scanning, continuous compliance enforcement), and Respond to vulnerabilities (CVE updates, vulnerability disclosure, Auto DevOps, vulnerability reports, integrated learning tools, on-demand scanning).