How GitLab tracks vulnerabilities through refactors and reformatting ↗
Learn how GitLab's improved Scope+Offset fingerprinting keeps vulnerability tracking stable across comments, blank lines, and reformatting.
13 posts
Learn how GitLab's improved Scope+Offset fingerprinting keeps vulnerability tracking stable across comments, blank lines, and reformatting.
AI coding agents are useful, but unguarded ones cause real damage. agentbox is a Docker-based sandbox that constrains what they can reach.
Learn how this security feature improves the efficiency of vulnerability management by reducing futile auditing time (includes data from a new study).
How the SourceWarp approach and tool help make informed, agile decisions for CI/CD tools and DevSecOps platforms at GitLab.
Our 2022 Google Summer of Code project helped to create a benchmarking framework for SAST.
Design, build and integrate your own Domain Specific Language with Lingo.
A KISS (keep it short and simple) MagpieBridge server implementation.
The advisory data can be readily adopted, adapted, and exchanged. Learn more here.
SemVer versioning made it difficult to automate processing. We turned to linear interval arithmetic to come up with a unified, language-agnostic semantic versioning approach.
Interns with the Google Summer of Code helped GitLab transition from our old SAST tools to Semgrep.
A read-eval-print loop (REPL) is an interactive environment that reacts to user-input. REPL-driven development is a very interactive programming style with a short feedback cycle enabling …
No posts match that search.