Custom Compliance Frameworks
GitLab strengthens supply chain with compliance features

GitLab strengthens supply chain with compliance features

2/9/2022 · Cindy Blake

What this post added

This post details the introduction of Infrastructure as Code (IaC) scanning for configuration files (YAML, Kubernetes, CloudFormation, Terraform), the switch to Trivy for container scanning, and beta testing for production container scanning and cluster image scanning. It also highlights the use of Peach Tech and Fuzzit technology for API security and beta testing of DAST for APIs. New security governance features include continuous compliance with compliant workflow automation and a policy editor for fine-grained risk management rules. The post also announces the consolidation of security findings into a unified vulnerability management dashboard and the replacement of some open-source SAST scanners with Semgrep. Future plans include production container scanning, a DAST API scanner, API Discovery, compliance checks in MRs, group-level governance, full software supply chain security, inline security training, and intelligent code security.

Read the original post ↗