
9/19/2024 · Salman Ladha
What this post added
Introduces Advanced SAST, a new scanner powered by acquired Oxeye technology, which uses taint analysis and in-house security research to identify exploitable vulnerabilities with lower false-positive rates. It integrates natively into the GitLab DevSecOps platform, providing contextual remediation and integrating with GitLab Duo Enterprise AI. The feature is available in GitLab 17.3+ and will be enabled by default no later than GitLab 18.0. Future plans include upgrading more languages, real-time IDE scanning, and incremental scanning.