
10/22/2020 · Taylor McCaslin
What this post added
This post details GitLab's approach to building security features in the open, leveraging open-source projects and community contributions. It highlights the integration of various security scanning tools (SAST, DAST, Container Scanning, Dependency Scanning, License Scanning, Secret Detection, API Fuzzing, Coverage Fuzzing) directly into the DevOps lifecycle to 'shift left'. It also introduces an open integration framework for third-party tools and showcases community contributions in areas like Mobile SAST, Helm Chart support, fuzzing performance, secret detection, dependency scanning, OS updates, and .NET Framework support.