
10/6/2020 · Wayne Haber
What this post added
This post analyzes security vulnerability trends across thousands of projects hosted on GitLab.com, identifying trends in CWEs like Improper Input Validation, Out of Bounds Write, and Uncontrolled Resource Consumption. It highlights the increasing prevalence of vulnerabilities in dependent libraries and the persistent use of vulnerable container components. Recommendations are provided for security practitioners, including regular security issue triage, applying security fixes for containers and project dependencies, implementing static and dynamic analysis, secure secret storage, and web application security evaluations. The post also details trends observed in dependency scanning, container scanning, and static analysis, emphasizing the importance of tuning SAST scanners and securely handling secrets.