
4/2/2020 · Wayne Haber
What this post added
This post details the top 6 security trends observed in GitLab-hosted projects between September 2019 and February 2020. It identifies 'Components with known vulnerabilities' as the most prevalent, followed by XSS, lack of secret management, CSP, CSRF, and SQL injection. The post also highlights a significant increase in the use of GitLab's security scanning tools (SAST, DAST, dependency scanning, container scanning, secret detection) and a substantial rise in CSP vulnerabilities. It provides best practices for mitigating each vulnerability type and notes trends in their prevalence.