
6/1/2021 · Cindy Blake
What this post added
This post details GitLab's evolution in DevSecOps, emphasizing the integration of security testing into the CI pipeline, unified tooling for security and development teams, and improved remediation workflows. It highlights new features like compliant pipeline configurations using Compliance Frameworks, Security Alert Dashboard, bulk vulnerability status updates, Admin Mode, Semgrep integration for custom SAST rules, custom CA certificates, email alerts for key expirations, SAML enforcement for Git activity, on-demand DAST, and a new browser-based DAST crawler. It also mentions acquisitions of Peach Tech and Fuzz It for fuzzing capabilities and ML technology to innovate app sec. The post also touches on Professional Services for security training, migration, and advisory services, and positions GitLab to help meet challenges posed by the U.S. Executive Order on Improving the Nation's Cybersecurity.