Security Control Framework
How open source contributions accelerate GitLab Secure

How open source contributions accelerate GitLab Secure

10/22/2020 · Taylor McCaslin

What this post added

This post details GitLab's approach to building security features in the open, leveraging open-source projects and community contributions. It highlights the integration of various security scanning tools (SAST, DAST, Container Scanning, Dependency Scanning, License Scanning, Secret Detection, API Fuzzing, Coverage Fuzzing) directly into the DevOps lifecycle to 'shift left'. It also introduces an open integration framework for third-party tools and showcases community contributions in areas like Mobile SAST, Helm Chart support, fuzzing performance, secret detection, dependency scanning, OS updates, and .NET Framework support.

Read the original post ↗