[{"data":1,"prerenderedAt":1885},["ShallowReactive",2],{"/blog/2025-owasp-top-10-whats-changed-and-why-it-matters":3,"navigation-en-us":1100,"banner-en-us":1528,"footer-en-us":1538,"blog-post-authors-en-us-Fernando Diaz":1783,"blog-related-posts-en-us-2025-owasp-top-10-whats-changed-and-why-it-matters":1798,"blog-promotions-en-us":1822,"next-steps-en-us":1875},{"id":4,"title":5,"authors":6,"body":8,"category":1083,"date":1084,"description":1085,"extension":1086,"externalUrl":1087,"faq":1087,"featured":1088,"heroImage":1089,"meta":1090,"navigation":1091,"path":1092,"seo":1093,"slug":1094,"stem":1095,"tags":1096,"template":1098,"updatedDate":1087,"__hash__":1099},"blogPosts/en-us/blog/2025-owasp-top-10-whats-changed-and-why-it-matters.md","OWASP Top 10 2025: What's changed and why it matters",[7],"Fernando Diaz",{"type":9,"value":10,"toc":1058},"minimark",[11,22,33,38,41,44,51,56,73,77,94,98,101,104,107,111,144,147,173,194,209,218,222,226,231,234,238,255,259,282,286,289,292,295,312,315,338,341,344,347,351,368,371,387,391,394,397,400,417,420,436,440,443,446,449,469,472,488,492,495,498,501,518,521,544,548,551,554,557,574,577,598,602,605,608,611,628,631,654,658,661,664,667,684,687,710,713,716,719,722,742,745,768,772,775,780,839,845,852,856,904,910,915,919,955,961,966,970,995,1001,1006,1010,1042],[12,13,14,15,21],"p",{},"The OWASP Foundation has released the ",[16,17,20],"a",{"href":18,"rel":19},"https://owasp.org/Top10/2025/0x00_2025-Introduction/",[],"eighth edition of its influential \"Top 10 Security Risks\" list for 2025",",\nintroducing significant changes that reflect the evolving landscape of application security. Based on analysis\nof more than 175,000 Common Vulnerabilities and Exposures (CVEs) records and feedback from security practitioners across the globe, this update addresses\nmodern attack vectors. Here's everything you need to know about what's changed, why these changes matter,\nand how to protect your systems.",[23,24,25],"blockquote",{},[12,26,27,28],{},"💡 Join GitLab Transcend on February 10 to learn how agentic AI transforms software delivery. Hear from customers and discover how to jumpstart your own modernization journey. ",[16,29,32],{"href":30,"rel":31},"https://about.gitlab.com/events/transcend/virtual/",[],"Register now.",[34,35,37],"h2",{"id":36},"whats-new-in-2025","What's new in 2025?",[12,39,40],{},"The shift from 2021 (the last time the list came out) to 2025 represents more than minor adjustments, it's a fundamental shift in application security.\nTwo entirely new categories entered the list and one category was consolidated into another, which highlights emerging risks\nthat traditional testing often misses.",[12,42,43],{},"These additions and shifts can be seen in the chart below:",[12,45,46],{},[47,48],"img",{"alt":49,"src":50},"OWASP Top 10 - Changes from 2021 to 2025","https://res.cloudinary.com/about-gitlab-com/image/upload/v1767639428/tbekzibeqylorwqrkdau.png",[52,53,55],"h3",{"id":54},"two-new-categories","Two new categories",[57,58,59,67],"ul",{},[60,61,62,66],"li",{},[63,64,65],"strong",{},"A03: Software Supply Chain Failures",": Expands the 2021 category \"Vulnerable and Outdated Components\" to encompass the entire software supply chain, including dependencies, build systems, and distribution infrastructure. Despite having the fewest occurrences in testing data, this category has the highest average exploit and impact scores from CVEs.",[60,68,69,72],{},[63,70,71],{},"A10: Mishandling of Exceptional Conditions",": Focuses on improper error handling, logical errors, and failing open scenarios. This addresses how systems respond to abnormal conditions.",[52,74,76],{"id":75},"major-ranking-changes","Major ranking changes",[57,78,79,82,85,88,91],{},[60,80,81],{},"Security Misconfiguration surged from #5 (2021) to #2 (2025), now affecting 3% of tested applications.",[60,83,84],{},"Server-Side Request Forgery (SSRF) has been consolidated into A01: Broken Access Control.",[60,86,87],{},"Cryptographic Failures dropped from #2 to #4.",[60,89,90],{},"Injection fell from #3 to #5.",[60,92,93],{},"Insecure Design moved from #4 to #6.",[34,95,97],{"id":96},"why-these-changes-were-made","Why these changes were made",[12,99,100],{},"The OWASP methodology combines data-driven analysis with community insights. The 2025 edition analyzed 589\nCommon Weakness Enumerations (CWEs), which is a substantial increase from the approximately 400 CWEs in 2021.\nThis expansion reflects the growing complexity of modern software systems and the need to capture emerging threats.",[12,102,103],{},"The community survey component addresses a fundamental limitation: testing data essentially looks into the past.\nBy the time security researchers develop testing methodologies and integrate them into automated tools, years may\nhave passed. The two community-voted categories ensure that emerging risks identified by frontline practitioners\nare included, even if they're not yet prevalent in automated testing data.",[12,105,106],{},"The rise of Security Misconfiguration highlights an industry trend toward configuration-based security,\nwhile Software Supply Chain Failures acknowledges the rise of sophisticated attacks targeting compromised packages.",[34,108,110],{"id":109},"using-gitlab-ultimate-for-vulnerability-detection-and-management","Using GitLab Ultimate for vulnerability detection and management",[12,112,113,114,119,120,125,126,131,132,137,138,143],{},"GitLab Ultimate provides comprehensive ",[16,115,118],{"href":116,"rel":117},"https://docs.gitlab.com/user/application_security/detect/",[],"security scanning"," to detect risks across the\n2025 OWASP Top 10 categories. For instance, the end-to-end platform analyzes your project's source code, dependencies, and infrastructure\ndefinitions. It also uses ",[16,121,124],{"href":122,"rel":123},"https://docs.gitlab.com/user/application_security/sast/gitlab_advanced_sast/",[],"Advanced Static Application Security Testing (SAST)"," to detect injection flaws,\ncryptographic failures, and insecure design patterns in source code. ",[16,127,130],{"href":128,"rel":129},"https://docs.gitlab.com/user/application_security/iac_scanning/",[],"Infrastructure as Code (IaC) scanning"," finds\nsecurity misconfigurations in your deployment definitions. ",[16,133,136],{"href":134,"rel":135},"https://docs.gitlab.com/user/application_security/secret_detection/",[],"Secret Detection"," prevents the leakage of credentials, and\n",[16,139,142],{"href":140,"rel":141},"https://docs.gitlab.com/user/application_security/dependency_scanning/",[],"Dependency Scanning"," uncovers libraries with known vulnerabilities in your software supply chain, which directly\naddresses the new A03 category for Software Supply Chain Failures.",[12,145,146],{},"In addition:",[57,148,149,157,165],{},[60,150,151,156],{},[16,152,155],{"href":153,"rel":154},"https://docs.gitlab.com/user/application_security/dast/",[],"Dynamic Application Security Testing (DAST)"," probes your deployed application for broken access control,\nauthentication failures, and injection vulnerabilities by simulating attack vectors.",[60,158,159,164],{},[16,160,163],{"href":161,"rel":162},"https://docs.gitlab.com/user/application_security/api_security/",[],"API Security Testing","\nprobes your API endpoints for input validation weaknesses and authentication bypasses.",[60,166,167,172],{},[16,168,171],{"href":169,"rel":170},"https://docs.gitlab.com/user/application_security/api_fuzzing/",[],"Web API Fuzz Testing","\nuncovers how your application handles exceptional conditions by generating unexpected inputs, which directly\naddresses the new A10 category for mishandling of exceptional conditions.",[12,174,175,176,181,182,187,188,193],{},"Security scanning integrates seamlessly into your ",[16,177,180],{"href":178,"rel":179},"https://about.gitlab.com/topics/ci-cd/",[],"CI/CD pipeline",", running when code is pushed from a feature\nbranch so developers can remediate vulnerabilities before they reach production. Security findings are consolidated in\nthe ",[16,183,186],{"href":184,"rel":185},"https://docs.gitlab.com/user/application_security/vulnerability_report/",[],"Vulnerability Report",", where security\nteams can triage, analyze, and track remediation. GitLab also allows you to leverage AI agents such as ",[16,189,192],{"href":190,"rel":191},"https://about.gitlab.com/blog/vulnerability-triage-made-simple-with-gitlab-security-analyst-agent/",[],"Security Analyst Agent",", available in GitLab Duo Agent Platform, to quickly determine what are the most critical vulnerabilities and how to take action on\nthem.",[12,195,196,197,202,203,208],{},"You can enforce additional controls through ",[16,198,201],{"href":199,"rel":200},"https://docs.gitlab.com/user/application_security/policies/merge_request_approval_policies/",[],"merge request approval policies"," and ",[16,204,207],{"href":205,"rel":206},"https://docs.gitlab.com/user/application_security/policies/pipeline_execution_policies/",[],"pipeline execution policies"," to ensure security scanning runs consistently across your organization. Customer Success and Professional Services teams at GitLab ensure you derive value from an investment in GitLab in a timely manner.",[12,210,211,212,217],{},"Deliver secure software faster with security testing in the same platform developers already use.\nTo learn more, visit our ",[16,213,216],{"href":214,"rel":215},"https://about.gitlab.com/solutions/application-security-testing/",[],"application security testing solutions site",".",[34,219,221],{"id":220},"the-owasp-top-10-2025-complete-breakdown","The OWASP Top 10 2025: Complete breakdown",[52,223,225],{"id":224},"a01-broken-access-control","A01: Broken Access Control",[227,228,230],"h5",{"id":229},"what-it-is","What it is",[12,232,233],{},"Failures in enforcing policies that prevent users from acting outside their intended permissions,\nleading to unauthorized access.",[227,235,237],{"id":236},"impact-on-your-system","Impact on your system",[57,239,240,243,246,249,252],{},[60,241,242],{},"Unauthorized information disclosure",[60,244,245],{},"Complete data destruction or data modification",[60,247,248],{},"Privilege escalation (users gaining admin rights)",[60,250,251],{},"Viewing or editing other users' accounts",[60,253,254],{},"API access from unauthorized or untrusted sources",[227,256,258],{"id":257},"notable-cwes","Notable CWEs",[57,260,261,268,275],{},[60,262,263],{},[16,264,267],{"href":265,"rel":266},"https://cwe.mitre.org/data/definitions/22.html",[],"CWE-22: Path Traversal",[60,269,270],{},[16,271,274],{"href":272,"rel":273},"https://cwe.mitre.org/data/definitions/200.html",[],"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",[60,276,277],{},[16,278,281],{"href":279,"rel":280},"https://cwe.mitre.org/data/definitions/352.html",[],"CWE-352: Cross-Site Request Forgery (CSRF)",[52,283,285],{"id":284},"a02-security-misconfiguration","A02: Security Misconfiguration",[227,287,230],{"id":288},"what-it-is-1",[12,290,291],{},"Systems, applications, or cloud services configured incorrectly from a security perspective.",[227,293,237],{"id":294},"impact-on-your-system-1",[57,296,297,300,303,306,309],{},[60,298,299],{},"Exposure of sensitive information through error messages",[60,301,302],{},"Unauthorized access through default accounts",[60,304,305],{},"Unnecessary services or features enabled",[60,307,308],{},"Outdated security patches",[60,310,311],{},"Server does not send security headers or directives",[227,313,258],{"id":314},"notable-cwes-1",[57,316,317,324,331],{},[60,318,319],{},[16,320,323],{"href":321,"rel":322},"https://cwe.mitre.org/data/definitions/16.html",[],"CWE-16: Configuration",[60,325,326],{},[16,327,330],{"href":328,"rel":329},"https://cwe.mitre.org/data/definitions/521.html",[],"CWE-521: Weak Password Requirements",[60,332,333],{},[16,334,337],{"href":335,"rel":336},"https://cwe.mitre.org/data/definitions/798.html",[],"CWE-798: Use of Hard-coded Credentials",[52,339,65],{"id":340},"a03-software-supply-chain-failures",[227,342,230],{"id":343},"what-it-is-2",[12,345,346],{},"Breakdowns or compromises in building, distributing, or updating software through vulnerabilities or malicious changes in dependencies, tools, or build processes.",[227,348,350],{"id":349},"impact-on-your-system-2","Impact on your system:",[57,352,353,356,359,362,365],{},[60,354,355],{},"Compromised packages introducing backdoors",[60,357,358],{},"Malicious code injected during build processes",[60,360,361],{},"Vulnerable dependencies cascading through your application",[60,363,364],{},"Use of components from untrusted sources in production",[60,366,367],{},"Changes within your supply chain are not tracked",[227,369,258],{"id":370},"notable-cwes-2",[57,372,373,380],{},[60,374,375],{},[16,376,379],{"href":377,"rel":378},"https://cwe.mitre.org/data/definitions/1395.html",[],"CWE-1395: Dependency on Vulnerable Third-Party Component",[60,381,382],{},[16,383,386],{"href":384,"rel":385},"https://cwe.mitre.org/data/definitions/1104.html",[],"CWE-1104: Use of Unmaintained Third Party Components",[52,388,390],{"id":389},"a04-cryptographic-failures","A04: Cryptographic Failures",[227,392,230],{"id":393},"what-it-is-3",[12,395,396],{},"Failures related to lack of cryptography, insufficiently strong cryptography, leaking of cryptographic keys, and related errors.",[227,398,350],{"id":399},"impact-on-your-system-3",[57,401,402,405,408,411,414],{},[60,403,404],{},"Sensitive data exposure (passwords, credit cards, health records)",[60,406,407],{},"Man-in-the-middle attacks",[60,409,410],{},"Data breach through weak encryption",[60,412,413],{},"Key compromise leading to system-wide exposure",[60,415,416],{},"Regulatory compliance failures (GDPR, PCI DSS)",[227,418,258],{"id":419},"notable-cwes-3",[57,421,422,429],{},[60,423,424],{},[16,425,428],{"href":426,"rel":427},"https://cwe.mitre.org/data/definitions/327.html",[],"CWE-327: Use of a Broken or Risky Cryptographic Algorithm",[60,430,431],{},[16,432,435],{"href":433,"rel":434},"https://cwe.mitre.org/data/definitions/330.html",[],"CWE-330: Use of Insufficiently Random Values",[52,437,439],{"id":438},"a05-injection","A05: Injection",[227,441,230],{"id":442},"what-it-is-4",[12,444,445],{},"System flaws allowing attackers to insert malicious code or commands (SQL, NoSQL, OS commands, LDAP, etc.) into programs.",[227,447,237],{"id":448},"impact-on-your-system-4",[57,450,451,454,457,460,463,466],{},[60,452,453],{},"Data loss or corruption through SQL injection",[60,455,456],{},"Complete database compromise",[60,458,459],{},"Server takeover through command injection",[60,461,462],{},"Cross-site scripting (XSS) attacks",[60,464,465],{},"Information disclosure",[60,467,468],{},"Denial of service",[227,470,258],{"id":471},"notable-cwes-4",[57,473,474,481],{},[60,475,476],{},[16,477,480],{"href":478,"rel":479},"https://cwe.mitre.org/data/definitions/89.html",[],"CWE-89: SQL Injection",[60,482,483],{},[16,484,487],{"href":485,"rel":486},"https://cwe.mitre.org/data/definitions/78.html",[],"CWE-78: OS Command Injection",[52,489,491],{"id":490},"a06-insecure-design","A06: Insecure Design",[227,493,230],{"id":494},"what-it-is-5",[12,496,497],{},"Weaknesses in design representing different failures, expressed as missing or ineffective control design—architectural flaws rather than implementation bugs.",[227,499,237],{"id":500},"impact-on-your-system-5",[57,502,503,506,509,512,515],{},[60,504,505],{},"Weak password reset flows",[60,507,508],{},"Missing authorization steps",[60,510,511],{},"Flawed business logic allowing bypasses",[60,513,514],{},"Inadequate threat modeling leading to blind spots",[60,516,517],{},"Design patterns that fail under attack scenarios",[227,519,258],{"id":520},"notable-cwes-5",[57,522,523,530,537],{},[60,524,525],{},[16,526,529],{"href":527,"rel":528},"https://cwe.mitre.org/data/definitions/209.html",[],"CWE-209: Generation of Error Messages Containing Sensitive Information",[60,531,532],{},[16,533,536],{"href":534,"rel":535},"https://cwe.mitre.org/data/definitions/522.html",[],"CWE-522: Insufficiently Protected Credentials",[60,538,539],{},[16,540,543],{"href":541,"rel":542},"https://cwe.mitre.org/data/definitions/656.html",[],"CWE-656: Reliance on Security Through Obscurity",[52,545,547],{"id":546},"a07-authentication-failures","A07: Authentication Failures",[227,549,230],{"id":550},"what-it-is-6",[12,552,553],{},"Vulnerabilities allowing attackers to trick systems into recognizing invalid or incorrect users as legitimate.",[227,555,237],{"id":556},"impact-on-your-system-6",[57,558,559,562,565,568,571],{},[60,560,561],{},"Account takeover and credential stuffing",[60,563,564],{},"Session hijacking",[60,566,567],{},"Brute force attacks succeeding",[60,569,570],{},"Weak password recovery mechanisms exploited",[60,572,573],{},"Multi-factor authentication bypass",[227,575,258],{"id":576},"notable-cwes-6",[57,578,579,586,593],{},[60,580,581],{},[16,582,585],{"href":583,"rel":584},"https://cwe.mitre.org/data/definitions/287.html",[],"CWE-287: Improper Authentication",[60,587,588],{},[16,589,592],{"href":590,"rel":591},"https://cwe.mitre.org/data/definitions/306.html",[],"CWE-306: Missing Authentication for Critical Function",[60,594,595],{},[16,596,330],{"href":328,"rel":597},[],[52,599,601],{"id":600},"a08-software-or-data-integrity-failures","A08: Software or Data Integrity Failures",[227,603,230],{"id":604},"what-it-is-7",[12,606,607],{},"Code and infrastructure failing to protect against invalid or untrusted code/data being treated as trusted and valid.",[227,609,237],{"id":610},"impact-on-your-system-7",[57,612,613,616,619,622,625],{},[60,614,615],{},"Unsigned updates allowing malicious code injection",[60,617,618],{},"Insecure deserialization leading to remote code execution",[60,620,621],{},"CI/CD pipeline compromise",[60,623,624],{},"Auto-update mechanisms exploited",[60,626,627],{},"Tampered software artifacts",[227,629,258],{"id":630},"notable-cwes-7",[57,632,633,640,647],{},[60,634,635],{},[16,636,639],{"href":637,"rel":638},"https://cwe.mitre.org/data/definitions/345.html",[],"CWE-345: Insufficient Verification of Data Authenticity",[60,641,642],{},[16,643,646],{"href":644,"rel":645},"https://cwe.mitre.org/data/definitions/346.html",[],"CWE-346: Origin Validation Error",[60,648,649],{},[16,650,653],{"href":651,"rel":652},"https://cwe.mitre.org/data/definitions/347.html",[],"CWE-347: Improper Verification of Cryptographic Signature",[52,655,657],{"id":656},"a09-security-logging-alerting-failures","A09: Security Logging & Alerting Failures",[227,659,230],{"id":660},"what-it-is-8",[12,662,663],{},"Insufficient logging and monitoring with inadequate alerting, which makes rapid response difficult.",[227,665,237],{"id":666},"impact-on-your-system-8",[57,668,669,672,675,678,681],{},[60,670,671],{},"Attacks go undetected for extended periods",[60,673,674],{},"Breach investigation becomes impossible",[60,676,677],{},"Compliance violations from lack of audit trails",[60,679,680],{},"Delayed incident response",[60,682,683],{},"Inability to determine scope of compromise",[227,685,258],{"id":686},"notable-cwes-8",[57,688,689,696,703],{},[60,690,691],{},[16,692,695],{"href":693,"rel":694},"https://cwe.mitre.org/data/definitions/117.html",[],"CWE-117: Improper Output Neutralization for Logs",[60,697,698],{},[16,699,702],{"href":700,"rel":701},"https://cwe.mitre.org/data/definitions/532.html",[],"CWE-532: Insertion of Sensitive Information into Log File",[60,704,705],{},[16,706,709],{"href":707,"rel":708},"https://cwe.mitre.org/data/definitions/778.html",[],"CWE-778: Insufficient Logging",[52,711,71],{"id":712},"a10-mishandling-of-exceptional-conditions",[227,714,230],{"id":715},"what-it-is-9",[12,717,718],{},"Programs failing to prevent, detect, and respond to unusual and unpredictable situations, which leads to crashes, unexpected behavior, or vulnerabilities.",[227,720,237],{"id":721},"impact-on-your-system-9",[57,723,724,727,730,733,736,739],{},[60,725,726],{},"Information disclosure through verbose error messages",[60,728,729],{},"Denial of service from unhandled exceptions",[60,731,732],{},"State corruption from improper error handling",[60,734,735],{},"Race conditions exploited",[60,737,738],{},"Systems failing open instead of closed",[60,740,741],{},"Application crashes exposing sensitive data",[227,743,258],{"id":744},"notable-cwes-9",[57,746,747,754,761],{},[60,748,749],{},[16,750,753],{"href":751,"rel":752},"https://cwe.mitre.org/data/definitions/248.html",[],"CWE-248: Uncaught Exception",[60,755,756],{},[16,757,760],{"href":758,"rel":759},"https://cwe.mitre.org/data/definitions/390.html",[],"CWE-390: Detection of Error Condition Without Action",[60,762,763],{},[16,764,767],{"href":765,"rel":766},"https://cwe.mitre.org/data/definitions/391.html",[],"CWE-391: Unchecked Error Condition",[34,769,771],{"id":770},"prevention-and-remediation-best-practices","Prevention and remediation best practices",[12,773,774],{},"GitLab provides tools to enable you to not only quickly find and remediate vulnerabilities within the OWASP Top 10,\nbut also to prevent them from making it into your production system. By following these best practices you can enhance\nand maintain your security posture:",[776,777,779],"h4",{"id":778},"automated-security-scanning-for-all-repositories","Automated security scanning for all repositories",[57,781,782,791,797,804,810,818,825,833],{},[60,783,784,785,790],{},"Perform ",[16,786,789],{"href":787,"rel":788},"https://docs.gitlab.com/user/application_security/sast/",[],"SAST Scanning"," to detect insecure design patterns like plaintext password storage, inadequate error handling, and missing encryption during code review, catching design flaws early in the development lifecycle.",[60,792,784,793,796],{},[16,794,136],{"href":134,"rel":795},[]," to identify credentials in configuration files, environment variables, and code, preventing plaintext password storage and ensuring secrets are properly managed through GitLab's CI/CD variables with masking and encryption.",[60,798,784,799,803],{},[16,800,802],{"href":153,"rel":801},[],"DAST Scanning"," to detect broken access control vulnerabilities",[60,805,784,806,809],{},[16,807,142],{"href":140,"rel":808},[]," to scan project dependencies against vulnerability databases, identifying known CVEs in direct and transitive dependencies across multiple package managers (npm, pip, Maven, etc.).",[60,811,784,812,817],{},[16,813,816],{"href":814,"rel":815},"https://docs.gitlab.com/user/application_security/container_scanning/",[],"Container Scanning"," to analyze Docker images for vulnerable base layers and packages, ensuring container supply chain security before deployment.",[60,819,784,820,824],{},[16,821,823],{"href":128,"rel":822},[],"IaC Scanning"," to check your infrastructure definition files for known vulnerabilities.",[60,826,827,828,832],{},"Leverage ",[16,829,831],{"href":161,"rel":830},[],"API Security Tools"," to secure and protect web APIs from unauthorized access, misuse, and attacks.",[60,834,784,835,838],{},[16,836,171],{"href":169,"rel":837},[]," to discover bugs and potential vulnerabilities that other QA processes might miss.",[12,840,841],{},[47,842],{"alt":843,"src":844},"Security Results in MR","https://res.cloudinary.com/about-gitlab-com/image/upload/v1767639431/zs6xh8hz6mud3vuig3dy.png",[846,847,848],"center",{},[849,850,851],"em",{},"View vulnerabilities detected in MR with diff from feature branch to main branch.",[776,853,855],{"id":854},"understand-your-security-posture","Understand your security posture",[57,857,858,867,874,887,896],{},[60,859,860,861,866],{},"Generate a ",[16,862,865],{"href":863,"rel":864},"https://docs.gitlab.com/user/application_security/dependency_list/",[],"software bill of materials (SBOM)"," for complete dependency visibility and compliance requirements.",[60,868,869,870,873],{},"Leverage the ",[16,871,186],{"href":184,"rel":872},[]," to sort through and triage vulnerabilites via consolidated view of security vulnerabilities found in your codebase.",[60,875,876,877,202,882,217],{},"Quickly take action on vulnerabilities using ",[16,878,881],{"href":879,"rel":880},"https://docs.gitlab.com/user/application_security/vulnerabilities/",[],"detailed remdiation guidance",[16,883,886],{"href":884,"rel":885},"https://docs.gitlab.com/user/application_security/vulnerabilities/risk_assessment_data/",[],"risk assessment data",[60,888,889,890,895],{},"Use ",[16,891,894],{"href":892,"rel":893},"https://docs.gitlab.com/user/application_security/security_inventory/",[],"Security Iventory"," to visualize which assets you need to secure and understand the actions you need to take to improve security.",[60,897,827,898,903],{},[16,899,902],{"href":900,"rel":901},"https://docs.gitlab.com/user/compliance/compliance_center/",[],"Compliance Center"," to manage compliance standards adherence reporting, violations reporting, and compliance frameworks.",[12,905,906],{},[47,907],{"alt":908,"src":909},"Security Inventory","https://res.cloudinary.com/about-gitlab-com/image/upload/v1767639429/e9vnakc8yiyjbjm8aj7s.png",[846,911,912],{},[849,913,914],{},"Use Security Inventory to viewing enabled security scanners and vulnerabilities.",[776,916,918],{"id":917},"set-up-prevention-and-maintain-documentation","Set up prevention and maintain documentation",[57,920,921,930,938,946,949,952],{},[60,922,923,924,929],{},"Configure ",[16,925,928],{"href":926,"rel":927},"https://docs.gitlab.com/user/application_security/policies/",[],"Security Policies"," to block merges or deployments when high-severity vulnerabilities are detected in dependencies, enforcing security standards automatically.",[60,931,889,932,937],{},[16,933,936],{"href":934,"rel":935},"https://docs.gitlab.com/user/compliance/compliance_frameworks/",[],"Compliance Frameworks"," to enforce organizational security standards through automated policy checks that verify encryption requirements, credential management practices, and secure workflow implementations are followed.",[60,939,940,941,217],{},"Use GitLab Wiki and repository documentation to maintain security design principles, approved patterns, and architectural decision records that guide developers toward ",[16,942,945],{"href":943,"rel":944},"https://about.gitlab.com/blog/last-year-we-signed-the-secure-by-design-pledge-heres-our-progress/",[],"secure-by-design implementations",[60,947,948],{},"Implement merge request approval rules requiring security architect review for features involving authentication, authorization, encryption, or sensitive data handling, ensuring design-level security validation.",[60,950,951],{},"Create tests to verify input validation and allowlist approaches for file paths",[60,953,954],{},"Use GitLab Issues and Epics to document security requirements and threat models during the design phase, creating a traceable record of security decisions and ensuring security considerations are addressed before implementation begins.",[12,956,957],{},[47,958],{"alt":959,"src":960},"Security Policy Dashboard","https://res.cloudinary.com/about-gitlab-com/image/upload/v1767639429/q4eelq3rqt0oonzhwoyb.png",[846,962,963],{},[849,964,965],{},"View and set Security Policies scoped to instance, group, or project.",[776,967,969],{"id":968},"leverage-ai","Leverage AI",[57,971,972,980,987],{},[60,973,889,974,979],{},[16,975,978],{"href":976,"rel":977},"https://docs.gitlab.com/user/project/repository/code_suggestions/",[],"Code Suggestions"," for proactive guidance during development, suggesting secure design patterns like proper password hashing (bcrypt, Argon2), encrypted storage mechanisms, and appropriate error handling that doesn't leak sensitive information.",[60,981,889,982,986],{},[16,983,192],{"href":984,"rel":985},"https://docs.gitlab.com/user/duo_agent_platform/agents/foundational_agents/security_analyst_agent/",[]," to review detected insecure design vulnerabilities in context, explaining the architectural implications, assessing risk based on your application's threat model, and providing remediation strategies that address root design flaws rather than just symptoms.",[60,988,989,994],{},[16,990,993],{"href":991,"rel":992},"https://docs.gitlab.com/user/project/merge_requests/duo_in_merge_requests/#have-gitlab-duo-review-your-code",[],"Review your code using AI"," to help ensure consistent code review standards in your project.",[12,996,997],{},[47,998],{"alt":999,"src":1000},"GitLab Security Analyst Agent","https://res.cloudinary.com/about-gitlab-com/image/upload/v1767639430/kqvgagepwleabt5zdkco.png",[846,1002,1003],{},[849,1004,1005],{},"Leverage Security Analyst Agent to quickly triage and assess security vulnerabilities.",[34,1007,1009],{"id":1008},"key-takeaways-for-development-teams","Key takeaways for development teams",[57,1011,1012,1018,1024,1030,1036],{},[60,1013,1014,1017],{},[63,1015,1016],{},"Supply chain security is critical",": With A03's addition and high-impact scores, securing your software supply chain is no longer optional. Implement SBOM tracking, dependency scanning, and integrity verification throughout your pipeline.",[60,1019,1020,1023],{},[63,1021,1022],{},"Configuration matters more than ever",": The rise to #2 shows that configuration-based security is now a primary attack vector. Automate configuration verification and implement IaC with security baked in.",[60,1025,1026,1029],{},[63,1027,1028],{},"Traditional threats persist",": While Injection and Cryptographic Failures dropped in ranking, they remain critical. Don't deprioritize them just because they've fallen on the list.",[60,1031,1032,1035],{},[63,1033,1034],{},"Error handling is security",": The new A10 category emphasizes that how your application handles failures is a security concern. Implement secure error handling from the start.",[60,1037,1038,1041],{},[63,1039,1040],{},"Testing must evolve",": The expanded CWE coverage (589 vs. 400 in 2021) means testing strategies must be comprehensive. Combine SAST, DAST, source code analysis, and manual penetration testing for effective coverage.",[23,1043,1044],{},[12,1045,1046,1047,1051,1052,1057],{},"Explore our ",[16,1048,1050],{"href":214,"rel":1049},[],"GitLab Security and Governance Solutions"," and\n",[16,1053,1056],{"href":1054,"rel":1055},"https://docs.gitlab.com/user/application_security/",[],"security scanning documentation"," to start strengthening your\nsecurity posture today.",{"title":1059,"searchDepth":1060,"depth":1060,"links":1061},"",2,[1062,1067,1068,1069,1081,1082],{"id":36,"depth":1060,"text":37,"children":1063},[1064,1066],{"id":54,"depth":1065,"text":55},3,{"id":75,"depth":1065,"text":76},{"id":96,"depth":1060,"text":97},{"id":109,"depth":1060,"text":110},{"id":220,"depth":1060,"text":221,"children":1070},[1071,1072,1073,1074,1075,1076,1077,1078,1079,1080],{"id":224,"depth":1065,"text":225},{"id":284,"depth":1065,"text":285},{"id":340,"depth":1065,"text":65},{"id":389,"depth":1065,"text":390},{"id":438,"depth":1065,"text":439},{"id":490,"depth":1065,"text":491},{"id":546,"depth":1065,"text":547},{"id":600,"depth":1065,"text":601},{"id":656,"depth":1065,"text":657},{"id":712,"depth":1065,"text":71},{"id":770,"depth":1060,"text":771},{"id":1008,"depth":1060,"text":1009},"security","2026-01-07","Explore new supply chain and error handling risks, ranking shifts, and remediation strategies for all 10 categories.","md",null,false,"https://res.cloudinary.com/about-gitlab-com/image/upload/v1759320418/xjmqcozxzt4frx0hori3.png",{},true,"/en-us/blog/2025-owasp-top-10-whats-changed-and-why-it-matters",{"title":5,"description":1085},"2025-owasp-top-10-whats-changed-and-why-it-matters","en-us/blog/2025-owasp-top-10-whats-changed-and-why-it-matters",[1083,1097],"open source","BlogPost","MICpAzl_z9l9p_M3EQWFvySDxfJhON8G8t_pG0DIWsY",{"logo":1101,"freeTrial":1106,"sales":1111,"login":1116,"items":1121,"search":1448,"minimal":1479,"duo":1498,"switchNav":1507,"pricingDeployment":1518},{"config":1102},{"href":1103,"dataGaName":1104,"dataGaLocation":1105},"/","gitlab logo","header",{"text":1107,"config":1108},"Get free trial",{"href":1109,"dataGaName":1110,"dataGaLocation":1105},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com&glm_content=default-saas-trial/","free trial",{"text":1112,"config":1113},"Request a demo",{"href":1114,"dataGaName":1115,"dataGaLocation":1105},"/sales/?contact-topic=request-demo","sales",{"text":1117,"config":1118},"Sign in",{"href":1119,"dataGaName":1120,"dataGaLocation":1105},"https://gitlab.com/users/sign_in/","sign in",[1122,1151,1251,1256,1370,1426],{"text":1123,"config":1124,"menu":1126},"Platform",{"dataNavLevelOne":1125},"platform",{"type":1127,"columns":1128},"cards",[1129,1135,1143],{"title":1123,"description":1130,"link":1131},"The intelligent orchestration platform for DevSecOps",{"text":1132,"config":1133},"Explore our Platform",{"href":1134,"dataGaName":1125,"dataGaLocation":1105},"/platform/",{"title":1136,"description":1137,"link":1138},"GitLab Duo Agent Platform","Agentic AI for the entire software lifecycle",{"text":1139,"config":1140},"Meet GitLab Duo",{"href":1141,"dataGaName":1142,"dataGaLocation":1105},"/gitlab-duo-agent-platform/","gitlab duo agent platform",{"title":1144,"description":1145,"link":1146},"Why GitLab","See the top reasons enterprises choose GitLab",{"text":1147,"config":1148},"Learn more",{"href":1149,"dataGaName":1150,"dataGaLocation":1105},"/why-gitlab/","why gitlab",{"text":1152,"left":1091,"config":1153,"menu":1155},"Product",{"dataNavLevelOne":1154},"solutions",{"type":1156,"link":1157,"columns":1161,"feature":1230},"lists",{"text":1158,"config":1159},"View all Solutions",{"href":1160,"dataGaName":1154,"dataGaLocation":1105},"/solutions/",[1162,1186,1209],{"title":1163,"description":1164,"link":1165,"items":1170},"Automation","CI/CD and automation to accelerate deployment",{"config":1166},{"icon":1167,"href":1168,"dataGaName":1169,"dataGaLocation":1105},"AutomatedCodeAlt","/solutions/delivery-automation/","automated software delivery",[1171,1175,1178,1182],{"text":1172,"config":1173},"CI/CD",{"href":1174,"dataGaLocation":1105,"dataGaName":1172},"/solutions/continuous-integration/",{"text":1136,"config":1176},{"href":1141,"dataGaLocation":1105,"dataGaName":1177},"gitlab duo agent platform - product menu",{"text":1179,"config":1180},"Source Code Management",{"href":1181,"dataGaLocation":1105,"dataGaName":1179},"/solutions/source-code-management/",{"text":1183,"config":1184},"Automated Software Delivery",{"href":1168,"dataGaLocation":1105,"dataGaName":1185},"Automated software delivery",{"title":1187,"description":1188,"link":1189,"items":1194},"Security","Deliver code faster without compromising security",{"config":1190},{"href":1191,"dataGaName":1192,"dataGaLocation":1105,"icon":1193},"/solutions/application-security-testing/","security and compliance","ShieldCheckLight",[1195,1199,1204],{"text":1196,"config":1197},"Application Security Testing",{"href":1191,"dataGaName":1198,"dataGaLocation":1105},"Application security testing",{"text":1200,"config":1201},"Software Supply Chain Security",{"href":1202,"dataGaLocation":1105,"dataGaName":1203},"/solutions/supply-chain/","Software supply chain security",{"text":1205,"config":1206},"Software Compliance",{"href":1207,"dataGaName":1208,"dataGaLocation":1105},"/solutions/software-compliance/","software compliance",{"title":1210,"link":1211,"items":1216},"Measurement",{"config":1212},{"icon":1213,"href":1214,"dataGaName":1215,"dataGaLocation":1105},"DigitalTransformation","/solutions/visibility-measurement/","visibility and measurement",[1217,1221,1225],{"text":1218,"config":1219},"Visibility & Measurement",{"href":1214,"dataGaLocation":1105,"dataGaName":1220},"Visibility and Measurement",{"text":1222,"config":1223},"Value Stream Management",{"href":1224,"dataGaLocation":1105,"dataGaName":1222},"/solutions/value-stream-management/",{"text":1226,"config":1227},"Analytics & Insights",{"href":1228,"dataGaLocation":1105,"dataGaName":1229},"/solutions/analytics-and-insights/","Analytics and insights",{"title":1231,"type":1156,"items":1232},"GitLab for",[1233,1239,1245],{"text":1234,"config":1235},"Enterprise",{"icon":1236,"href":1237,"dataGaLocation":1105,"dataGaName":1238},"Building","/enterprise/","enterprise",{"text":1240,"config":1241},"Small Business",{"icon":1242,"href":1243,"dataGaLocation":1105,"dataGaName":1244},"Work","/small-business/","small business",{"text":1246,"config":1247},"Public Sector",{"icon":1248,"href":1249,"dataGaLocation":1105,"dataGaName":1250},"Organization","/solutions/public-sector/","public sector",{"text":1252,"config":1253},"Pricing",{"href":1254,"dataGaName":1255,"dataGaLocation":1105,"dataNavLevelOne":1255},"/pricing/","pricing",{"text":1257,"config":1258,"menu":1260},"Resources",{"dataNavLevelOne":1259},"resources",{"type":1156,"link":1261,"columns":1265,"feature":1359},{"text":1262,"config":1263},"View all resources",{"href":1264,"dataGaName":1259,"dataGaLocation":1105},"/resources/",[1266,1299,1326],{"title":1267,"items":1268},"Getting started",[1269,1274,1279,1284,1289,1294],{"text":1270,"config":1271},"Install",{"href":1272,"dataGaName":1273,"dataGaLocation":1105},"/install/","install",{"text":1275,"config":1276},"Quick start guides",{"href":1277,"dataGaName":1278,"dataGaLocation":1105},"/get-started/","quick setup checklists",{"text":1280,"config":1281},"Learn",{"href":1282,"dataGaLocation":1105,"dataGaName":1283},"https://university.gitlab.com/","learn",{"text":1285,"config":1286},"Product documentation",{"href":1287,"dataGaName":1288,"dataGaLocation":1105},"https://docs.gitlab.com/","product documentation",{"text":1290,"config":1291},"Best practice videos",{"href":1292,"dataGaName":1293,"dataGaLocation":1105},"/getting-started-videos/","best practice videos",{"text":1295,"config":1296},"Integrations",{"href":1297,"dataGaName":1298,"dataGaLocation":1105},"/integrations/","integrations",{"title":1300,"items":1301},"Discover",[1302,1307,1312,1317,1321],{"text":1303,"config":1304},"Customer success stories",{"href":1305,"dataGaName":1306,"dataGaLocation":1105},"/customers/","customer success stories",{"text":1308,"config":1309},"Blog",{"href":1310,"dataGaName":1311,"dataGaLocation":1105},"/blog/","blog",{"text":1313,"config":1314},"Demo Hub",{"href":1315,"dataGaName":1316,"dataGaLocation":1105},"/demo-hub/","demo hub",{"text":1318,"config":1319},"The Source",{"href":1320,"dataGaName":1311,"dataGaLocation":1105},"/the-source/",{"text":1322,"config":1323},"Remote",{"href":1324,"dataGaName":1325,"dataGaLocation":1105},"https://handbook.gitlab.com/handbook/company/culture/all-remote/","remote",{"title":1327,"items":1328},"Connect",[1329,1334,1339,1344,1349,1354],{"text":1330,"config":1331},"GitLab Services",{"href":1332,"dataGaName":1333,"dataGaLocation":1105},"/services/","services",{"text":1335,"config":1336},"Contribute",{"href":1337,"dataGaName":1338,"dataGaLocation":1105},"https://contributors.gitlab.com","contribute",{"text":1340,"config":1341},"Community",{"href":1342,"dataGaName":1343,"dataGaLocation":1105},"/community/","community",{"text":1345,"config":1346},"Forum",{"href":1347,"dataGaName":1348,"dataGaLocation":1105},"https://forum.gitlab.com/","forum",{"text":1350,"config":1351},"Events",{"href":1352,"dataGaName":1353,"dataGaLocation":1105},"/events/","events",{"text":1355,"config":1356},"Partners",{"href":1357,"dataGaName":1358,"dataGaLocation":1105},"/partners/","partners",{"config":1360,"title":1363,"text":1364,"link":1365},{"background":1361,"textColor":1362},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1777322348/qpq8yrgn8knii57omj0c.png')","#000","What’s new in GitLab","Stay updated with our latest features and improvements.",{"text":1366,"config":1367},"Read the latest",{"href":1368,"dataGaName":1369,"dataGaLocation":1105},"/whats-new/","whats new",{"text":1371,"config":1372,"menu":1374},"Company",{"dataNavLevelOne":1373},"company",{"type":1156,"columns":1375},[1376],{"items":1377},[1378,1383,1389,1391,1396,1401,1406,1411,1416,1421],{"text":1379,"config":1380},"About",{"href":1381,"dataGaName":1382,"dataGaLocation":1105},"/company/","about",{"text":1384,"config":1385,"footerGa":1388},"Jobs",{"href":1386,"dataGaName":1387,"dataGaLocation":1105},"/jobs/","jobs",{"dataGaName":1387},{"text":1350,"config":1390},{"href":1352,"dataGaName":1353,"dataGaLocation":1105},{"text":1392,"config":1393},"Leadership",{"href":1394,"dataGaName":1395,"dataGaLocation":1105},"/company/team/e-group/","leadership",{"text":1397,"config":1398},"Handbook",{"href":1399,"dataGaName":1400,"dataGaLocation":1105},"https://handbook.gitlab.com/","handbook",{"text":1402,"config":1403},"Investor relations",{"href":1404,"dataGaName":1405,"dataGaLocation":1105},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":1407,"config":1408},"Trust Center",{"href":1409,"dataGaName":1410,"dataGaLocation":1105},"/security/","trust center",{"text":1412,"config":1413},"AI Transparency Center",{"href":1414,"dataGaName":1415,"dataGaLocation":1105},"/ai-transparency-center/","ai transparency center",{"text":1417,"config":1418},"Newsletter",{"href":1419,"dataGaName":1420,"dataGaLocation":1105},"/company/contact/#contact-forms","newsletter",{"text":1422,"config":1423},"Press",{"href":1424,"dataGaName":1425,"dataGaLocation":1105},"/press/","press",{"text":1427,"config":1428,"menu":1429},"Contact us",{"dataNavLevelOne":1373},{"type":1156,"columns":1430},[1431],{"items":1432},[1433,1438,1443],{"text":1434,"config":1435},"Talk to sales",{"href":1436,"dataGaName":1437,"dataGaLocation":1105},"/sales/","talk to sales",{"text":1439,"config":1440},"Support portal",{"href":1441,"dataGaName":1442,"dataGaLocation":1105},"https://support.gitlab.com/hc/en-us","support portal",{"text":1444,"config":1445},"Customer portal",{"href":1446,"dataGaName":1447,"dataGaLocation":1105},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":1449,"login":1450,"suggestions":1457},"Close",{"text":1451,"link":1452},"To search repositories and projects, login to",{"text":1453,"config":1454},"gitlab.com",{"href":1119,"dataGaName":1455,"dataGaLocation":1456},"search login","search",{"text":1458,"default":1459},"Suggestions",[1460,1462,1466,1468,1472,1476],{"text":1136,"config":1461},{"href":1141,"dataGaName":1136,"dataGaLocation":1456},{"text":1463,"config":1464},"Code Suggestions (AI)",{"href":1465,"dataGaName":1463,"dataGaLocation":1456},"/solutions/code-suggestions/",{"text":1172,"config":1467},{"href":1174,"dataGaName":1172,"dataGaLocation":1456},{"text":1469,"config":1470},"GitLab on AWS",{"href":1471,"dataGaName":1469,"dataGaLocation":1456},"/partners/technology-partners/aws/",{"text":1473,"config":1474},"GitLab on Google Cloud",{"href":1475,"dataGaName":1473,"dataGaLocation":1456},"/partners/technology-partners/google-cloud-platform/",{"text":1477,"config":1478},"Why GitLab?",{"href":1149,"dataGaName":1477,"dataGaLocation":1456},{"freeTrial":1480,"mobileIcon":1485,"desktopIcon":1490,"secondaryButton":1493},{"text":1481,"config":1482},"Start free trial",{"href":1483,"dataGaName":1110,"dataGaLocation":1484},"https://gitlab.com/-/trials/new/","nav",{"altText":1486,"config":1487},"Gitlab Icon",{"src":1488,"dataGaName":1489,"dataGaLocation":1484},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":1486,"config":1491},{"src":1492,"dataGaName":1489,"dataGaLocation":1484},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":1494,"config":1495},"Get Started",{"href":1496,"dataGaName":1497,"dataGaLocation":1484},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/get-started/","get started",{"freeTrial":1499,"mobileIcon":1503,"desktopIcon":1505},{"text":1500,"config":1501},"Learn more about GitLab Duo",{"href":1141,"dataGaName":1502,"dataGaLocation":1484},"gitlab duo",{"altText":1486,"config":1504},{"src":1488,"dataGaName":1489,"dataGaLocation":1484},{"altText":1486,"config":1506},{"src":1492,"dataGaName":1489,"dataGaLocation":1484},{"button":1508,"mobileIcon":1513,"desktopIcon":1515},{"text":1509,"config":1510},"/switch",{"href":1511,"dataGaName":1512,"dataGaLocation":1484},"#contact","switch",{"altText":1486,"config":1514},{"src":1488,"dataGaName":1489,"dataGaLocation":1484},{"altText":1486,"config":1516},{"src":1517,"dataGaName":1489,"dataGaLocation":1484},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":1519,"mobileIcon":1524,"desktopIcon":1526},{"text":1520,"config":1521},"Back to pricing",{"href":1254,"dataGaName":1522,"dataGaLocation":1484,"icon":1523},"back to pricing","GoBack",{"altText":1486,"config":1525},{"src":1488,"dataGaName":1489,"dataGaLocation":1484},{"altText":1486,"config":1527},{"src":1492,"dataGaName":1489,"dataGaLocation":1484},{"title":1529,"titleMobile":1530,"button":1531,"config":1536},"Duo Agent Platform delivers 400% ROI, per new Forrester Consulting study.","400% ROI: Forrester TEI for GitLab Duo",{"text":1147,"config":1532},{"href":1533,"dataGaName":1534,"dataGaLocation":1535},"https://about.gitlab.com/blog/gitlab-duo-agent-platform-delivers-400-percent-roi/","forrester-tei-dap-banner","global-banner",{"layout":1537,"disabled":1088},"release",{"data":1539},{"text":1540,"source":1541,"edit":1547,"contribute":1552,"config":1557,"items":1562,"minimal":1772},"Git is a trademark of Software Freedom Conservancy and our use of 'GitLab' is under license",{"text":1542,"config":1543},"View page source",{"href":1544,"dataGaName":1545,"dataGaLocation":1546},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":1548,"config":1549},"Edit this page",{"href":1550,"dataGaName":1551,"dataGaLocation":1546},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":1553,"config":1554},"Please contribute",{"href":1555,"dataGaName":1556,"dataGaLocation":1546},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":1558,"facebook":1559,"youtube":1560,"linkedin":1561},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[1563,1610,1664,1708,1740],{"title":1252,"links":1564,"subMenu":1579},[1565,1569,1574],{"text":1566,"config":1567},"View plans",{"href":1254,"dataGaName":1568,"dataGaLocation":1546},"view plans",{"text":1570,"config":1571},"Why Premium?",{"href":1572,"dataGaName":1573,"dataGaLocation":1546},"/pricing/premium/","why premium",{"text":1575,"config":1576},"Why Ultimate?",{"href":1577,"dataGaName":1578,"dataGaLocation":1546},"/pricing/ultimate/","why ultimate",[1580],{"title":1581,"links":1582},"Contact Us",[1583,1586,1588,1590,1595,1600,1605],{"text":1584,"config":1585},"Contact sales",{"href":1436,"dataGaName":1115,"dataGaLocation":1546},{"text":1439,"config":1587},{"href":1441,"dataGaName":1442,"dataGaLocation":1546},{"text":1444,"config":1589},{"href":1446,"dataGaName":1447,"dataGaLocation":1546},{"text":1591,"config":1592},"Status",{"href":1593,"dataGaName":1594,"dataGaLocation":1546},"https://status.gitlab.com/","status",{"text":1596,"config":1597},"Terms of use",{"href":1598,"dataGaName":1599,"dataGaLocation":1546},"/terms/","terms of use",{"text":1601,"config":1602},"Privacy statement",{"href":1603,"dataGaName":1604,"dataGaLocation":1546},"/privacy/","privacy statement",{"text":1606,"config":1607},"Cookie preferences",{"dataGaName":1608,"dataGaLocation":1546,"id":1609,"isOneTrustButton":1091},"cookie preferences","ot-sdk-btn",{"title":1152,"links":1611,"subMenu":1620},[1612,1616],{"text":1613,"config":1614},"DevSecOps platform",{"href":1134,"dataGaName":1615,"dataGaLocation":1546},"devsecops platform",{"text":1617,"config":1618},"AI-Assisted Development",{"href":1141,"dataGaName":1619,"dataGaLocation":1546},"ai-assisted development",[1621],{"title":1622,"links":1623},"Topics",[1624,1629,1634,1639,1644,1649,1654,1659],{"text":1625,"config":1626},"CICD",{"href":1627,"dataGaName":1628,"dataGaLocation":1546},"/topics/ci-cd/","cicd",{"text":1630,"config":1631},"GitOps",{"href":1632,"dataGaName":1633,"dataGaLocation":1546},"/topics/gitops/","gitops",{"text":1635,"config":1636},"DevOps",{"href":1637,"dataGaName":1638,"dataGaLocation":1546},"/topics/devops/","devops",{"text":1640,"config":1641},"Version Control",{"href":1642,"dataGaName":1643,"dataGaLocation":1546},"/topics/version-control/","version control",{"text":1645,"config":1646},"DevSecOps",{"href":1647,"dataGaName":1648,"dataGaLocation":1546},"/topics/devsecops/","devsecops",{"text":1650,"config":1651},"Cloud Native",{"href":1652,"dataGaName":1653,"dataGaLocation":1546},"/topics/cloud-native/","cloud native",{"text":1655,"config":1656},"AI for Coding",{"href":1657,"dataGaName":1658,"dataGaLocation":1546},"/topics/devops/ai-for-coding/","ai for coding",{"text":1660,"config":1661},"Agentic AI",{"href":1662,"dataGaName":1663,"dataGaLocation":1546},"/topics/agentic-ai/","agentic ai",{"title":1665,"links":1666},"Solutions",[1667,1669,1671,1676,1680,1683,1687,1690,1692,1695,1698,1703],{"text":1196,"config":1668},{"href":1191,"dataGaName":1196,"dataGaLocation":1546},{"text":1185,"config":1670},{"href":1168,"dataGaName":1169,"dataGaLocation":1546},{"text":1672,"config":1673},"Agile development",{"href":1674,"dataGaName":1675,"dataGaLocation":1546},"/solutions/agile-delivery/","agile delivery",{"text":1677,"config":1678},"SCM",{"href":1181,"dataGaName":1679,"dataGaLocation":1546},"source code management",{"text":1625,"config":1681},{"href":1174,"dataGaName":1682,"dataGaLocation":1546},"continuous integration & delivery",{"text":1684,"config":1685},"Value stream management",{"href":1224,"dataGaName":1686,"dataGaLocation":1546},"value stream management",{"text":1630,"config":1688},{"href":1689,"dataGaName":1633,"dataGaLocation":1546},"/solutions/gitops/",{"text":1234,"config":1691},{"href":1237,"dataGaName":1238,"dataGaLocation":1546},{"text":1693,"config":1694},"Small business",{"href":1243,"dataGaName":1244,"dataGaLocation":1546},{"text":1696,"config":1697},"Public sector",{"href":1249,"dataGaName":1250,"dataGaLocation":1546},{"text":1699,"config":1700},"Education",{"href":1701,"dataGaName":1702,"dataGaLocation":1546},"/solutions/education/","education",{"text":1704,"config":1705},"Financial services",{"href":1706,"dataGaName":1707,"dataGaLocation":1546},"/solutions/finance/","financial services",{"title":1257,"links":1709},[1710,1712,1714,1716,1719,1721,1724,1726,1728,1730,1732,1734,1736,1738],{"text":1270,"config":1711},{"href":1272,"dataGaName":1273,"dataGaLocation":1546},{"text":1275,"config":1713},{"href":1277,"dataGaName":1278,"dataGaLocation":1546},{"text":1280,"config":1715},{"href":1282,"dataGaName":1283,"dataGaLocation":1546},{"text":1285,"config":1717},{"href":1287,"dataGaName":1718,"dataGaLocation":1546},"docs",{"text":1308,"config":1720},{"href":1310,"dataGaName":1311,"dataGaLocation":1546},{"text":1722,"config":1723},"What's new",{"href":1368,"dataGaName":1369,"dataGaLocation":1546},{"text":1303,"config":1725},{"href":1305,"dataGaName":1306,"dataGaLocation":1546},{"text":1322,"config":1727},{"href":1324,"dataGaName":1325,"dataGaLocation":1546},{"text":1330,"config":1729},{"href":1332,"dataGaName":1333,"dataGaLocation":1546},{"text":1335,"config":1731},{"href":1337,"dataGaName":1338,"dataGaLocation":1546},{"text":1340,"config":1733},{"href":1342,"dataGaName":1343,"dataGaLocation":1546},{"text":1345,"config":1735},{"href":1347,"dataGaName":1348,"dataGaLocation":1546},{"text":1350,"config":1737},{"href":1352,"dataGaName":1353,"dataGaLocation":1546},{"text":1355,"config":1739},{"href":1357,"dataGaName":1358,"dataGaLocation":1546},{"title":1371,"links":1741},[1742,1744,1746,1748,1750,1752,1756,1761,1763,1765,1767],{"text":1379,"config":1743},{"href":1381,"dataGaName":1373,"dataGaLocation":1546},{"text":1384,"config":1745},{"href":1386,"dataGaName":1387,"dataGaLocation":1546},{"text":1392,"config":1747},{"href":1394,"dataGaName":1395,"dataGaLocation":1546},{"text":1397,"config":1749},{"href":1399,"dataGaName":1400,"dataGaLocation":1546},{"text":1402,"config":1751},{"href":1404,"dataGaName":1405,"dataGaLocation":1546},{"text":1753,"config":1754},"Sustainability",{"href":1755,"dataGaName":1753,"dataGaLocation":1546},"/sustainability/",{"text":1757,"config":1758},"Diversity, inclusion and belonging (DIB)",{"href":1759,"dataGaName":1760,"dataGaLocation":1546},"/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":1407,"config":1762},{"href":1409,"dataGaName":1410,"dataGaLocation":1546},{"text":1417,"config":1764},{"href":1419,"dataGaName":1420,"dataGaLocation":1546},{"text":1422,"config":1766},{"href":1424,"dataGaName":1425,"dataGaLocation":1546},{"text":1768,"config":1769},"Modern Slavery Transparency Statement",{"href":1770,"dataGaName":1771,"dataGaLocation":1546},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":1773},[1774,1777,1780],{"text":1775,"config":1776},"Terms",{"href":1598,"dataGaName":1599,"dataGaLocation":1546},{"text":1778,"config":1779},"Cookies",{"dataGaName":1608,"dataGaLocation":1546,"id":1609,"isOneTrustButton":1091},{"text":1781,"config":1782},"Privacy",{"href":1603,"dataGaName":1604,"dataGaLocation":1546},[1784],{"id":1785,"title":7,"body":1087,"config":1786,"content":1788,"description":1087,"extension":1792,"meta":1793,"navigation":1091,"path":1794,"seo":1795,"stem":1796,"__hash__":1797},"blogAuthors/en-us/blog/authors/fernando-diaz.yml",{"template":1787},"BlogAuthor",{"name":7,"config":1789},{"headshot":1790,"ctfId":1791},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749659556/Blog/Author%20Headshots/fern_diaz.png","fjdiaz","yml",{},"/en-us/blog/authors/fernando-diaz",{},"en-us/blog/authors/fernando-diaz","lxRJIOydP4_yzYZvsPcuQevP9AYAKREF7i8QmmdnOWc",[1799,1806,1814],{"title":1800,"description":1801,"heroImage":1089,"category":1083,"date":1802,"authors":1803,"slug":1805,"externalUrl":1087},"How GitLab tracks vulnerabilities through refactors and reformatting","Learn how GitLab's improved Scope+Offset fingerprinting keeps vulnerability tracking stable across comments, blank lines, and reformatting.","2026-08-12",[1804],"Julian Thome","improved-scope-offset-fingerprinting",{"title":1807,"description":1808,"heroImage":1089,"category":1083,"date":1809,"authors":1810,"slug":1813,"externalUrl":1087},"GitLab Secrets Manager adds ESO, Terraform, API support","Simplify credential management across your stack. GitLab Secrets Manager provides secure retrieval in Kubernetes, Terraform, and external workflows.","2026-08-06",[1811,1812],"Erick Bajao","Joe Randazzo","gitlab-secrets-manager-add-eso-terraform-api-support",{"title":1815,"description":1816,"heroImage":1817,"category":1083,"date":1818,"authors":1819,"slug":1821,"externalUrl":1087},"Secure every commit to production with Claude and GitLab","Claude Security catches vulnerabilities inside a coding session. GitLab picks up from there, scanning, enforcing policy, and producing audit evidence for the software lifecycle. ","https://res.cloudinary.com/about-gitlab-com/image/upload/v1756122536/akivvcnafog9c4dhhzkp.png","2026-08-03",[1820],"Alisa Ho","claude-security-and-gitlab",{"promotions":1823},[1824,1838,1850,1861],{"id":1825,"categories":1826,"header":1828,"text":1829,"button":1830,"image":1835},"ai-modernization",[1827],"ai","Is AI achieving its promise at scale?","Quiz will take 5 minutes or less",{"text":1831,"config":1832},"Get your AI maturity score",{"href":1833,"dataGaName":1834,"dataGaLocation":1311},"/assessments/ai-modernization-assessment/","modernization assessment",{"config":1836},{"src":1837},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/qix0m7kwnd8x2fh1zq49.png",{"id":1839,"categories":1840,"header":1842,"text":1829,"button":1843,"image":1847},"devops-modernization",[1841,1648],"product","Are you just managing tools or shipping innovation?",{"text":1844,"config":1845},"Get your DevOps maturity score",{"href":1846,"dataGaName":1834,"dataGaLocation":1311},"/assessments/devops-modernization-assessment/",{"config":1848},{"src":1849},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138785/eg818fmakweyuznttgid.png",{"id":1851,"categories":1852,"header":1853,"text":1829,"button":1854,"image":1858},"security-modernization",[1083],"Are you trading speed for security?",{"text":1855,"config":1856},"Get your security maturity score",{"href":1857,"dataGaName":1834,"dataGaLocation":1311},"/assessments/security-modernization-assessment/",{"config":1859},{"src":1860},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/p4pbqd9nnjejg5ds6mdk.png",{"id":1862,"paths":1863,"header":1866,"text":1867,"button":1868,"image":1873},"github-azure-migration",[1864,1865],"migration-from-azure-devops-to-gitlab","integrating-azure-devops-scm-and-gitlab","Is your team ready for GitHub's Azure move?","GitHub is already rebuilding around Azure. Find out what it means for you.",{"text":1869,"config":1870},"See how GitLab compares to GitHub",{"href":1871,"dataGaName":1872,"dataGaLocation":1311},"/compare/gitlab-vs-github/github-azure-migration/","github azure migration",{"config":1874},{"src":1849},{"header":1876,"blurb":1877,"button":1878,"secondaryButton":1883},"Start building faster today","See what your team can do with the intelligent orchestration platform for DevSecOps.\n",{"text":1879,"config":1880},"Get your free trial",{"href":1881,"dataGaName":1110,"dataGaLocation":1882},"https://gitlab.com/-/trial_registrations/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/","feature",{"text":1584,"config":1884},{"href":1436,"dataGaName":1115,"dataGaLocation":1882},1786803727418]