
Self-managed users using outdated versions should update immediately.

We’re running a bug bounty contest November 1 thru December 3. Find a bug and be entered to win some sweet custom swag. What’s better than a contest? Increased bounty ranges!

Our security team upgraded to GitLab’s DAST 2. Here’s how and why we did it.

Learn how we put our threat model into action iteratively and expanded the process into a full-fledged standalone activity.

How we responded to Axosoft’s GitKraken software vulnerability affecting SSH keys and actions users should take.

SemVer versioning made it difficult to automate processing. We turned to linear interval arithmetic to come up with a unified, language-agnostic semantic versioning approach.

Interns with the Google Summer of Code helped GitLab transition from our old SAST tools to Semgrep.

The complexity of developer working environments make them more likely to be vulnerable to a drive-by attack. We talk about why and walk you through a real-life example from a recent disclosure here at GitLab, and provide tips to reduce the risk and impact of drive-by attacks.
All fields required