
4/10/2020 · Mark Loveless
What this post added
This post discusses GitLab's approach to managing open source security software, focusing on the "supply chain" of external packages used within the GitLab product. It highlights the importance of dedicated security personnel for analyzing internal and external code flaws, managing bug submissions, and proactively identifying vulnerabilities in open source dependencies. The article emphasizes GitLab's transparent and open-core model as a benefit for security disclosure and discusses the role of DevSecOps in rapid development with a security focus. Key takeaways for improving open source security include having dedicated, empowered security staff, strong upper management buy-in, fostering a culture that avoids shame and punishment for security issues, and making security a "muscle memory" practice.