
10/22/2024 · Fernando Diaz
What this post added
This post details the general availability of GitLab Advanced SAST, a new static application security testing scanner that performs cross-function and cross-file taint analysis. It outlines the prerequisites (Ultimate Subscription, GitLab 17.4+), configuration steps using `.gitlab-ci.yml`, and how to leverage the scanner's results within merge requests and the vulnerability report. It also highlights the integration with GitLab Duo Vulnerability Explanation for AI-powered remediation guidance, including a concrete example using OWASP Juice Shop.