
6/21/2022 · Fernando Diaz
What this post added
This post details enhancements to GitLab's application security features in GitLab 15, building upon the existing Custom Compliance Frameworks. New features include a global rule registry for policy customization, a browser-based DAST scanner for modern APIs and SPAs, expanded Semgrep support for SAST, and new vulnerability management capabilities. It also highlights the migration of SAST, Container Scanning, and Secret Detection to the Free tier. For Ultimate users, it introduces DAST, Operational Container Scanning, Dependency Scanning, IaC Scanning, Coverage-Guided Fuzzing, and Web-API Fuzzing. Enhancements to the developer lifecycle include a security widget in merge requests and the ability to create confidential issues for collaboration. The security team benefits from improved Vulnerability Reports, Security Dashboards, and the enforcement of separation of duties via Compliance Frameworks and Security Policies.