[{"data":1,"prerenderedAt":1255},["ShallowReactive",2],{"/blog/enhance-application-security-with-gitlab-hackerone":3,"navigation-en-us":474,"banner-en-us":899,"footer-en-us":909,"blog-post-authors-en-us-Fernando Diaz":1152,"blog-related-posts-en-us-enhance-application-security-with-gitlab-hackerone":1167,"blog-promotions-en-us":1192,"next-steps-en-us":1245},{"id":4,"title":5,"authors":6,"body":8,"category":450,"date":451,"description":452,"extension":453,"externalUrl":454,"faq":454,"featured":455,"heroImage":456,"meta":457,"navigation":281,"path":458,"seo":459,"slug":463,"stem":464,"tags":465,"template":472,"updatedDate":454,"__hash__":473},"blogPosts/en-us/blog/enhance-application-security-with-gitlab-hackerone.md","Enhance application security with GitLab + HackerOne",[7],"Fernando Diaz",{"type":9,"value":10,"toc":443},"minimark",[11,15,18,21,26,29,45,55,64,90,93,158,165,173,177,180,194,197,203,206,210,213,236,244,305,314,320,323,329,332,336,339,385,396,400,403,439],[12,13,14],"p",{},"Security can no longer be an afterthought in the development process. Organizations need robust solutions that integrate security throughout the entire software development lifecycle. This is where the partnership between HackerOne and GitLab creates a compelling combination for modern application development teams.",[12,16,17],{},"GitLab, the comprehensive, AI-powered DevSecOps platform, and HackerOne, the leading crowd-sourced security platform, have established a partnership that brings together the best of both worlds: GitLab's streamlined DevSecOps workflow and HackerOne's powerful vulnerability management capabilities.",[12,19,20],{},"In this tutorial, you'll learn how to enhance developer productivity and your security posture by implementing HackerOne's GitLab integration.",[22,23,25],"h2",{"id":24},"an-integration-that-empowers-developers","An integration that empowers developers",[12,27,28],{},"HackerOne's GitLab integration is remarkably straightforward, yet powerful. When security researchers discover vulnerabilities through HackerOne's platform, these findings are automatically converted into GitLab issues. This creates a seamless workflow where:",[30,31,32,36,39,42],"ul",{},[33,34,35],"li",{},"Security researchers identify vulnerabilities via HackerOne's platform",[33,37,38],{},"Validated vulnerabilities are automatically converted into GitLab issues",[33,40,41],{},"Development teams can address these issues directly within their existing workflow",[33,43,44],{},"Resolution status is synchronized between both platforms",[12,46,47,48,54],{},"You can start leveraging the benefits of GitLab and HackerOne by using the ",[49,50,53],"a",{"href":51,"rel":52},"https://docs.hackerone.com/en/articles/8571227-gitlab-integration",[],"integration"," to track GitLab issues as references on HackerOne. This integration provides bi-directional and seamless data syncing between your HackerOne report and GitLab issues, improving alignment between development and security teams while streamlining security vulnerability processing.",[12,56,57,58,63],{},"To configure the GitLab integration to sync information between your HackerOne report and your Gitlab issue, follow the instructions provided in ",[49,59,62],{"href":60,"rel":61},"https://docs.hackerone.com/en/articles/10394699-gitlab-setup",[],"HackerOne's GitLab integration documentation",", which includes:",[65,66,67,75,78,81,84,87],"ol",{},[33,68,69,74],{},[49,70,73],{"href":71,"rel":72},"https://docs.gitlab.com/integration/oauth_provider/",[],"Setting up an OAuth 2.0 application"," for your GitLab instance with the provided HackerOne settings",[33,76,77],{},"Connecting HackerOne to the newly created OAuth 2.0 on GitLab",[33,79,80],{},"Authorizing HackerOne to access the GitLab API",[33,82,83],{},"Configuring which GitLab project you would like to escalate HackerOne reports to",[33,85,86],{},"Selecting the HackerOne fields to map to corresponding GitLab fields",[33,88,89],{},"GitLab-to-HackerOne and HackerOne-to-GitLab event configuration",[12,91,92],{},"Once the integration is in place, you’ll be able to seamlessly sync data bi-directionally between both GitLab and HackerOne. This helps simplify context-switching and allows vulnerabilities to be tracked with ease throughout both systems. The integration allows for the following features:",[30,94,95,102,107,133,146,152],{},[33,96,97,101],{},[98,99,100],"strong",{},"Creating a GitLab Issue from HackerOne:"," You can create new GitLab issues for reports you receive on HackerOne.",[33,103,104],{},[98,105,106],{},"Linking HackerOne reports to existing GitLab tasks.",[33,108,109,112,113],{},[98,110,111],{},"Syncing updates from HackerOne to GitLab:"," The following updates on a report are synced as a comment to GitLab.\n",[30,114,115,118,121,124,127,130],{},[33,116,117],{},"Report comments",[33,119,120],{},"State changes",[33,122,123],{},"Rewards",[33,125,126],{},"Assignee changes",[33,128,129],{},"Public disclosure",[33,131,132],{},"Close GitLab Issue",[33,134,135,138,139],{},[98,136,137],{},"Syncing Updates from GitLab to HackerOne:"," The following updates on GitLab will be reflected in HackerOne as an internal comment on the associated report:\n",[30,140,141,144],{},[33,142,143],{},"Comments",[33,145,120],{},[33,147,148,151],{},[98,149,150],{},"HackerOne severity to GitLab label mapping",": Allows you to set a custom priority when escalating a report to GitLab.",[33,153,154,157],{},[98,155,156],{},"Due date mapping:"," Allows you to automatically set a custom due date based on the severity of a report.",[12,159,160],{},[161,162],"img",{"alt":163,"src":164},"GitLab + HackerOne adding comments or change the state of the report in GitLab","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750097510/Blog/Content%20Images/Blog/Content%20Images/sync_aHR0cHM6_1750097509644.png",[12,166,167,168,172],{},"These features improve alignment between development and security teams and streamlining security vulnerability processing. To learn more on how the integration works, see the ",[49,169,171],{"href":51,"rel":170},[],"integration documentation",".",[22,174,176],{"id":175},"a-look-into-hackerone-bug-bounty-programs","A look into HackerOne bug bounty programs",[12,178,179],{},"HackerOne provides bug bounty programs or cybersecurity initiatives where rewards are offered for discovering and reporting vulnerabilities in customers’ software systems, websites, or applications. Bug bounty programs help enhance the security of an application by:",[30,181,182,185,188,191],{},[33,183,184],{},"Identifying security flaws before malicious actors can exploit them",[33,186,187],{},"Leveraging diverse expertise from a global community of security researchers",[33,189,190],{},"Providing a cost-effective way to improve cybersecurity",[33,192,193],{},"Complementing internal security efforts and traditional penetration testing",[12,195,196],{},"GitLab utilizes HackerOne’s bug bounty program, allowing security researchers to report vulnerabilities in GitLab applications or infrastructure. This crowdsourced approach helps GitLab identify and address potential security issues more effectively.",[12,198,199],{},[161,200],{"alt":201,"src":202},"HackerOne GitLab Bug Bounty page","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750097510/Blog/Content%20Images/Blog/Content%20Images/hackerone_gitlab_bug_bounty_page_aHR0cHM6_1750097509645.png",[12,204,205],{},"By leveraging HackerOne's platform and the global hacker community, organizations can significantly enhance their security posture, identify vulnerabilities faster, and stay ahead of potential threats.",[22,207,209],{"id":208},"secure-applications-and-improve-efficiency-with-gitlab","Secure applications and improve efficiency with GitLab",[12,211,212],{},"GitLab provides a complete DevSecOps platform, which enables functionality for the complete software development lifecycle, including security and compliance tools. GitLab supports the following security scanner types:",[30,214,215,218,221,224,227,230,233],{},[33,216,217],{},"Static Application Security Testing (SAST)",[33,219,220],{},"Dynamic Application Security Testing (DAST)",[33,222,223],{},"Container Scanning",[33,225,226],{},"Dependency Scanning",[33,228,229],{},"Infrastructure as Code Scanning",[33,231,232],{},"Coverage-guided Fuzzing",[33,234,235],{},"Web API Fuzzing",[12,237,238,239,243],{},"With GitLab, you can add security scanning by simply applying a template to your CI/CD pipeline definition file. For example, enabling SAST just takes a few lines of code in the ",[240,241,242],"code",{},".gitlab-ci.yml",":",[245,246,251],"pre",{"className":247,"code":248,"language":249,"meta":250,"style":250},"language-yaml shiki shiki-themes github-light","stage:\n  - test\n\ninclude:\n  - template: Jobs/SAST.gitlab-ci.yml\n\n","yaml","",[240,252,253,266,276,283,291],{"__ignoreMap":250},[254,255,258,262],"span",{"class":256,"line":257},"line",1,[254,259,261],{"class":260},"shJU0","stage",[254,263,265],{"class":264},"sgsFI",":\n",[254,267,269,272],{"class":256,"line":268},2,[254,270,271],{"class":264},"  - ",[254,273,275],{"class":274},"sYBdl","test\n",[254,277,279],{"class":256,"line":278},3,[254,280,282],{"emptyLinePlaceholder":281},true,"\n",[254,284,286,289],{"class":256,"line":285},4,[254,287,288],{"class":260},"include",[254,290,265],{"class":264},[254,292,294,296,299,302],{"class":256,"line":293},5,[254,295,271],{"class":264},[254,297,298],{"class":260},"template",[254,300,301],{"class":264},": ",[254,303,304],{"class":274},"Jobs/SAST.gitlab-ci.yml\n",[12,306,307,308,313],{},"This will run SAST on the test stage, and ",[49,309,312],{"href":310,"rel":311},"https://docs.gitlab.com/user/application_security/sast/#supported-languages-and-frameworks",[],"auto-detect the languages used"," in your application. Then, whenever you create a merge request, SAST will detect the vulnerabilities in the diff between the feature branch and the target branch and provide relevant data on each vulnerability to assist with remediation.",[12,315,316],{},[161,317],{"alt":318,"src":319},"NoSQL injection vulnerability seen in MR","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750097510/Blog/Content%20Images/Blog/Content%20Images/no_sql_injection_vulnerability_mr_view_aHR0cHM6_1750097509647.png",[12,321,322],{},"The results of the SAST scanner can block code from being merged if security policies are applied. Native GitLab users can be set as approvers, allowing required reviews before merging insecure code. This assures that all vulnerabilities have oversight from the appropriate parties.",[12,324,325],{},[161,326],{"alt":327,"src":328},"Merge request approval policy","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750097510/Blog/Content%20Images/Blog/Content%20Images/merge_request_approval_policy_aHR0cHM6_1750097509649.png",[12,330,331],{},"HackerOne has integrated GitLab into its operations and development processes in several significant ways, which have led to development process improvements and enhanced scalability and collaboration. These improvements include faster deployments and cross-team planning.",[22,333,335],{"id":334},"key-benefits-of-hackerones-gitlab-integration","Key benefits of HackerOne's GitLab integration",[12,337,338],{},"The key benefits of using HackerOne and GitLab together include:",[30,340,341,347,353,359,365],{},[33,342,343,346],{},[98,344,345],{},"Enhanced security visibility:"," Development teams gain immediate visibility into security vulnerabilities without leaving their primary workflow environment. This real-time awareness helps teams prioritize security issues alongside feature development.",[33,348,349,352],{},[98,350,351],{},"Streamlined remediation process:"," By converting HackerOne reports directly into GitLab issues, the remediation process becomes part of the standard development cycle. This eliminates context switching between platforms and ensures security fixes are tracked alongside other development work.",[33,354,355,358],{},[98,356,357],{},"Accelerated time to fix:"," The integration significantly reduces the time between vulnerability discovery and resolution. With HackerOne submissions immediately available in GitLab, development teams can begin working on fixes without delay, improving overall security posture.",[33,360,361,364],{},[98,362,363],{},"Improved collaboration:"," Security researchers, security teams, and developers can communicate more effectively through this integration. Comments and updates flow between both platforms, creating a collaborative environment focused on improving security.",[33,366,367,370,371],{},[98,368,369],{},"Real-world impact:"," Organizations implementing the HackerOne and GitLab integration have reported:\n",[30,372,373,376,379,382],{},[33,374,375],{},"Up to 70% reduction in time from vulnerability discovery to fix",[33,377,378],{},"Improved developer satisfaction by keeping them in their preferred workflow",[33,380,381],{},"Enhanced security visibility across the organization",[33,383,384],{},"More effective allocation of security resources",[386,387,388],"blockquote",{},[12,389,390,391,395],{},"To get started today, visit ",[49,392,394],{"href":60,"rel":393},[],"the integration setup page"," today.",[22,397,399],{"id":398},"learn-more","Learn more",[12,401,402],{},"To learn more about GitLab and HackerOne, and how we can help enhance your security posture, check out the following resources:",[30,404,405,411,418,425,432],{},[33,406,407],{},[49,408,410],{"href":51,"rel":409},[],"HackerOne's GitLab Integration Usage",[33,412,413],{},[49,414,417],{"href":415,"rel":416},"https://hackerone.com/gitlab?type=team",[],"HackerOne GitLab Bug Bounty Program",[33,419,420],{},[49,421,424],{"href":422,"rel":423},"https://about.gitlab.com/solutions/application-security-testing/",[],"GitLab Security and Compliance Solutions",[33,426,427],{},[49,428,431],{"href":429,"rel":430},"https://about.gitlab.com/customers/hackerone/",[],"HackerOne achieves 5x faster deployments with GitLab’s integrated security",[33,433,434],{},[49,435,438],{"href":436,"rel":437},"https://docs.gitlab.com/user/application_security/",[],"GitLab Application Security Documentation",[440,441,442],"style",{},"html pre.shiki code .shJU0, html code.shiki .shJU0{--shiki-default:#22863A}html pre.shiki code .sgsFI, html code.shiki .sgsFI{--shiki-default:#24292E}html pre.shiki code .sYBdl, html code.shiki .sYBdl{--shiki-default:#032F62}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":250,"searchDepth":268,"depth":268,"links":444},[445,446,447,448,449],{"id":24,"depth":268,"text":25},{"id":175,"depth":268,"text":176},{"id":208,"depth":268,"text":209},{"id":334,"depth":268,"text":335},{"id":398,"depth":268,"text":399},"security","2025-04-03","Learn about the GitLab + HackerOne partnership and how to easily implement an integration that improves your organization’s application security posture.","md",null,false,"https://res.cloudinary.com/about-gitlab-com/image/upload/v1750097503/Blog/Hero%20Images/Blog/Hero%20Images/blog-image-template-1800x945%20%2810%29_5ET24Q6i8ihqrAOkge7a1R_1750097503214.png",{},"/en-us/blog/enhance-application-security-with-gitlab-hackerone",{"title":5,"description":452,"ogTitle":5,"ogDescription":452,"noIndex":455,"ogImage":456,"ogUrl":460,"ogSiteName":461,"ogType":462,"canonicalUrls":460},"https://about.gitlab.com/blog/enhance-application-security-with-gitlab-hackerone","https://about.gitlab.com","article","enhance-application-security-with-gitlab-hackerone","en-us/blog/enhance-application-security-with-gitlab-hackerone",[450,466,467,468,469,470,471],"tutorial","integrations","partners","DevSecOps platform","DevSecOps","bug bounty","BlogPost","RS0hVVGDtPES9rW39GzdC-oighAgbzmdYeVQ2g0Uyk0",{"logo":475,"freeTrial":480,"sales":485,"login":490,"items":495,"search":819,"minimal":850,"duo":869,"switchNav":878,"pricingDeployment":889},{"config":476},{"href":477,"dataGaName":478,"dataGaLocation":479},"/","gitlab logo","header",{"text":481,"config":482},"Get free trial",{"href":483,"dataGaName":484,"dataGaLocation":479},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com&glm_content=default-saas-trial/","free trial",{"text":486,"config":487},"Request a demo",{"href":488,"dataGaName":489,"dataGaLocation":479},"/sales/?contact-topic=request-demo","sales",{"text":491,"config":492},"Sign in",{"href":493,"dataGaName":494,"dataGaLocation":479},"https://gitlab.com/users/sign_in/","sign in",[496,524,624,629,741,797],{"text":497,"config":498,"menu":500},"Platform",{"dataNavLevelOne":499},"platform",{"type":501,"columns":502},"cards",[503,509,517],{"title":497,"description":504,"link":505},"The intelligent orchestration platform for DevSecOps",{"text":506,"config":507},"Explore our Platform",{"href":508,"dataGaName":499,"dataGaLocation":479},"/platform/",{"title":510,"description":511,"link":512},"GitLab Duo Agent Platform","Agentic AI for the entire software lifecycle",{"text":513,"config":514},"Meet GitLab Duo",{"href":515,"dataGaName":516,"dataGaLocation":479},"/gitlab-duo-agent-platform/","gitlab duo agent platform",{"title":518,"description":519,"link":520},"Why GitLab","See the top reasons enterprises choose GitLab",{"text":399,"config":521},{"href":522,"dataGaName":523,"dataGaLocation":479},"/why-gitlab/","why gitlab",{"text":525,"left":281,"config":526,"menu":528},"Product",{"dataNavLevelOne":527},"solutions",{"type":529,"link":530,"columns":534,"feature":603},"lists",{"text":531,"config":532},"View all Solutions",{"href":533,"dataGaName":527,"dataGaLocation":479},"/solutions/",[535,559,582],{"title":536,"description":537,"link":538,"items":543},"Automation","CI/CD and automation to accelerate deployment",{"config":539},{"icon":540,"href":541,"dataGaName":542,"dataGaLocation":479},"AutomatedCodeAlt","/solutions/delivery-automation/","automated software delivery",[544,548,551,555],{"text":545,"config":546},"CI/CD",{"href":547,"dataGaLocation":479,"dataGaName":545},"/solutions/continuous-integration/",{"text":510,"config":549},{"href":515,"dataGaLocation":479,"dataGaName":550},"gitlab duo agent platform - product menu",{"text":552,"config":553},"Source Code Management",{"href":554,"dataGaLocation":479,"dataGaName":552},"/solutions/source-code-management/",{"text":556,"config":557},"Automated Software Delivery",{"href":541,"dataGaLocation":479,"dataGaName":558},"Automated software delivery",{"title":560,"description":561,"link":562,"items":567},"Security","Deliver code faster without compromising security",{"config":563},{"href":564,"dataGaName":565,"dataGaLocation":479,"icon":566},"/solutions/application-security-testing/","security and compliance","ShieldCheckLight",[568,572,577],{"text":569,"config":570},"Application Security Testing",{"href":564,"dataGaName":571,"dataGaLocation":479},"Application security testing",{"text":573,"config":574},"Software Supply Chain Security",{"href":575,"dataGaLocation":479,"dataGaName":576},"/solutions/supply-chain/","Software supply chain security",{"text":578,"config":579},"Software Compliance",{"href":580,"dataGaName":581,"dataGaLocation":479},"/solutions/software-compliance/","software compliance",{"title":583,"link":584,"items":589},"Measurement",{"config":585},{"icon":586,"href":587,"dataGaName":588,"dataGaLocation":479},"DigitalTransformation","/solutions/visibility-measurement/","visibility and measurement",[590,594,598],{"text":591,"config":592},"Visibility & Measurement",{"href":587,"dataGaLocation":479,"dataGaName":593},"Visibility and Measurement",{"text":595,"config":596},"Value Stream Management",{"href":597,"dataGaLocation":479,"dataGaName":595},"/solutions/value-stream-management/",{"text":599,"config":600},"Analytics & Insights",{"href":601,"dataGaLocation":479,"dataGaName":602},"/solutions/analytics-and-insights/","Analytics and insights",{"title":604,"type":529,"items":605},"GitLab for",[606,612,618],{"text":607,"config":608},"Enterprise",{"icon":609,"href":610,"dataGaLocation":479,"dataGaName":611},"Building","/enterprise/","enterprise",{"text":613,"config":614},"Small Business",{"icon":615,"href":616,"dataGaLocation":479,"dataGaName":617},"Work","/small-business/","small business",{"text":619,"config":620},"Public Sector",{"icon":621,"href":622,"dataGaLocation":479,"dataGaName":623},"Organization","/solutions/public-sector/","public sector",{"text":625,"config":626},"Pricing",{"href":627,"dataGaName":628,"dataGaLocation":479,"dataNavLevelOne":628},"/pricing/","pricing",{"text":630,"config":631,"menu":633},"Resources",{"dataNavLevelOne":632},"resources",{"type":529,"link":634,"columns":638,"feature":730},{"text":635,"config":636},"View all resources",{"href":637,"dataGaName":632,"dataGaLocation":479},"/resources/",[639,671,698],{"title":640,"items":641},"Getting started",[642,647,652,657,662,667],{"text":643,"config":644},"Install",{"href":645,"dataGaName":646,"dataGaLocation":479},"/install/","install",{"text":648,"config":649},"Quick start guides",{"href":650,"dataGaName":651,"dataGaLocation":479},"/get-started/","quick setup checklists",{"text":653,"config":654},"Learn",{"href":655,"dataGaLocation":479,"dataGaName":656},"https://university.gitlab.com/","learn",{"text":658,"config":659},"Product documentation",{"href":660,"dataGaName":661,"dataGaLocation":479},"https://docs.gitlab.com/","product documentation",{"text":663,"config":664},"Best practice videos",{"href":665,"dataGaName":666,"dataGaLocation":479},"/getting-started-videos/","best practice videos",{"text":668,"config":669},"Integrations",{"href":670,"dataGaName":467,"dataGaLocation":479},"/integrations/",{"title":672,"items":673},"Discover",[674,679,684,689,693],{"text":675,"config":676},"Customer success stories",{"href":677,"dataGaName":678,"dataGaLocation":479},"/customers/","customer success stories",{"text":680,"config":681},"Blog",{"href":682,"dataGaName":683,"dataGaLocation":479},"/blog/","blog",{"text":685,"config":686},"Demo Hub",{"href":687,"dataGaName":688,"dataGaLocation":479},"/demo-hub/","demo hub",{"text":690,"config":691},"The Source",{"href":692,"dataGaName":683,"dataGaLocation":479},"/the-source/",{"text":694,"config":695},"Remote",{"href":696,"dataGaName":697,"dataGaLocation":479},"https://handbook.gitlab.com/handbook/company/culture/all-remote/","remote",{"title":699,"items":700},"Connect",[701,706,711,716,721,726],{"text":702,"config":703},"GitLab Services",{"href":704,"dataGaName":705,"dataGaLocation":479},"/services/","services",{"text":707,"config":708},"Contribute",{"href":709,"dataGaName":710,"dataGaLocation":479},"https://contributors.gitlab.com","contribute",{"text":712,"config":713},"Community",{"href":714,"dataGaName":715,"dataGaLocation":479},"/community/","community",{"text":717,"config":718},"Forum",{"href":719,"dataGaName":720,"dataGaLocation":479},"https://forum.gitlab.com/","forum",{"text":722,"config":723},"Events",{"href":724,"dataGaName":725,"dataGaLocation":479},"/events/","events",{"text":727,"config":728},"Partners",{"href":729,"dataGaName":468,"dataGaLocation":479},"/partners/",{"config":731,"title":734,"text":735,"link":736},{"background":732,"textColor":733},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1777322348/qpq8yrgn8knii57omj0c.png')","#000","What’s new in GitLab","Stay updated with our latest features and improvements.",{"text":737,"config":738},"Read the latest",{"href":739,"dataGaName":740,"dataGaLocation":479},"/whats-new/","whats new",{"text":742,"config":743,"menu":745},"Company",{"dataNavLevelOne":744},"company",{"type":529,"columns":746},[747],{"items":748},[749,754,760,762,767,772,777,782,787,792],{"text":750,"config":751},"About",{"href":752,"dataGaName":753,"dataGaLocation":479},"/company/","about",{"text":755,"config":756,"footerGa":759},"Jobs",{"href":757,"dataGaName":758,"dataGaLocation":479},"/jobs/","jobs",{"dataGaName":758},{"text":722,"config":761},{"href":724,"dataGaName":725,"dataGaLocation":479},{"text":763,"config":764},"Leadership",{"href":765,"dataGaName":766,"dataGaLocation":479},"/company/team/e-group/","leadership",{"text":768,"config":769},"Handbook",{"href":770,"dataGaName":771,"dataGaLocation":479},"https://handbook.gitlab.com/","handbook",{"text":773,"config":774},"Investor relations",{"href":775,"dataGaName":776,"dataGaLocation":479},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":778,"config":779},"Trust Center",{"href":780,"dataGaName":781,"dataGaLocation":479},"/security/","trust center",{"text":783,"config":784},"AI Transparency Center",{"href":785,"dataGaName":786,"dataGaLocation":479},"/ai-transparency-center/","ai transparency center",{"text":788,"config":789},"Newsletter",{"href":790,"dataGaName":791,"dataGaLocation":479},"/company/contact/#contact-forms","newsletter",{"text":793,"config":794},"Press",{"href":795,"dataGaName":796,"dataGaLocation":479},"/press/","press",{"text":798,"config":799,"menu":800},"Contact us",{"dataNavLevelOne":744},{"type":529,"columns":801},[802],{"items":803},[804,809,814],{"text":805,"config":806},"Talk to sales",{"href":807,"dataGaName":808,"dataGaLocation":479},"/sales/","talk to sales",{"text":810,"config":811},"Support portal",{"href":812,"dataGaName":813,"dataGaLocation":479},"https://support.gitlab.com/hc/en-us","support portal",{"text":815,"config":816},"Customer portal",{"href":817,"dataGaName":818,"dataGaLocation":479},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":820,"login":821,"suggestions":828},"Close",{"text":822,"link":823},"To search repositories and projects, login to",{"text":824,"config":825},"gitlab.com",{"href":493,"dataGaName":826,"dataGaLocation":827},"search login","search",{"text":829,"default":830},"Suggestions",[831,833,837,839,843,847],{"text":510,"config":832},{"href":515,"dataGaName":510,"dataGaLocation":827},{"text":834,"config":835},"Code Suggestions (AI)",{"href":836,"dataGaName":834,"dataGaLocation":827},"/solutions/code-suggestions/",{"text":545,"config":838},{"href":547,"dataGaName":545,"dataGaLocation":827},{"text":840,"config":841},"GitLab on AWS",{"href":842,"dataGaName":840,"dataGaLocation":827},"/partners/technology-partners/aws/",{"text":844,"config":845},"GitLab on Google Cloud",{"href":846,"dataGaName":844,"dataGaLocation":827},"/partners/technology-partners/google-cloud-platform/",{"text":848,"config":849},"Why GitLab?",{"href":522,"dataGaName":848,"dataGaLocation":827},{"freeTrial":851,"mobileIcon":856,"desktopIcon":861,"secondaryButton":864},{"text":852,"config":853},"Start free trial",{"href":854,"dataGaName":484,"dataGaLocation":855},"https://gitlab.com/-/trials/new/","nav",{"altText":857,"config":858},"Gitlab Icon",{"src":859,"dataGaName":860,"dataGaLocation":855},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":857,"config":862},{"src":863,"dataGaName":860,"dataGaLocation":855},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":865,"config":866},"Get Started",{"href":867,"dataGaName":868,"dataGaLocation":855},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/get-started/","get started",{"freeTrial":870,"mobileIcon":874,"desktopIcon":876},{"text":871,"config":872},"Learn more about GitLab Duo",{"href":515,"dataGaName":873,"dataGaLocation":855},"gitlab duo",{"altText":857,"config":875},{"src":859,"dataGaName":860,"dataGaLocation":855},{"altText":857,"config":877},{"src":863,"dataGaName":860,"dataGaLocation":855},{"button":879,"mobileIcon":884,"desktopIcon":886},{"text":880,"config":881},"/switch",{"href":882,"dataGaName":883,"dataGaLocation":855},"#contact","switch",{"altText":857,"config":885},{"src":859,"dataGaName":860,"dataGaLocation":855},{"altText":857,"config":887},{"src":888,"dataGaName":860,"dataGaLocation":855},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":890,"mobileIcon":895,"desktopIcon":897},{"text":891,"config":892},"Back to pricing",{"href":627,"dataGaName":893,"dataGaLocation":855,"icon":894},"back to pricing","GoBack",{"altText":857,"config":896},{"src":859,"dataGaName":860,"dataGaLocation":855},{"altText":857,"config":898},{"src":863,"dataGaName":860,"dataGaLocation":855},{"title":900,"titleMobile":901,"button":902,"config":907},"Duo Agent Platform delivers 400% ROI, per new Forrester Consulting study.","400% ROI: Forrester TEI for GitLab Duo",{"text":399,"config":903},{"href":904,"dataGaName":905,"dataGaLocation":906},"https://about.gitlab.com/blog/gitlab-duo-agent-platform-delivers-400-percent-roi/","forrester-tei-dap-banner","global-banner",{"layout":908,"disabled":455},"release",{"data":910},{"text":911,"source":912,"edit":918,"contribute":923,"config":928,"items":933,"minimal":1141},"Git is a trademark of Software Freedom Conservancy and our use of 'GitLab' is under license",{"text":913,"config":914},"View page source",{"href":915,"dataGaName":916,"dataGaLocation":917},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":919,"config":920},"Edit this page",{"href":921,"dataGaName":922,"dataGaLocation":917},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":924,"config":925},"Please contribute",{"href":926,"dataGaName":927,"dataGaLocation":917},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":929,"facebook":930,"youtube":931,"linkedin":932},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[934,981,1033,1077,1109],{"title":625,"links":935,"subMenu":950},[936,940,945],{"text":937,"config":938},"View plans",{"href":627,"dataGaName":939,"dataGaLocation":917},"view plans",{"text":941,"config":942},"Why Premium?",{"href":943,"dataGaName":944,"dataGaLocation":917},"/pricing/premium/","why premium",{"text":946,"config":947},"Why Ultimate?",{"href":948,"dataGaName":949,"dataGaLocation":917},"/pricing/ultimate/","why ultimate",[951],{"title":952,"links":953},"Contact Us",[954,957,959,961,966,971,976],{"text":955,"config":956},"Contact sales",{"href":807,"dataGaName":489,"dataGaLocation":917},{"text":810,"config":958},{"href":812,"dataGaName":813,"dataGaLocation":917},{"text":815,"config":960},{"href":817,"dataGaName":818,"dataGaLocation":917},{"text":962,"config":963},"Status",{"href":964,"dataGaName":965,"dataGaLocation":917},"https://status.gitlab.com/","status",{"text":967,"config":968},"Terms of use",{"href":969,"dataGaName":970,"dataGaLocation":917},"/terms/","terms of use",{"text":972,"config":973},"Privacy statement",{"href":974,"dataGaName":975,"dataGaLocation":917},"/privacy/","privacy statement",{"text":977,"config":978},"Cookie preferences",{"dataGaName":979,"dataGaLocation":917,"id":980,"isOneTrustButton":281},"cookie preferences","ot-sdk-btn",{"title":525,"links":982,"subMenu":990},[983,986],{"text":469,"config":984},{"href":508,"dataGaName":985,"dataGaLocation":917},"devsecops platform",{"text":987,"config":988},"AI-Assisted Development",{"href":515,"dataGaName":989,"dataGaLocation":917},"ai-assisted development",[991],{"title":992,"links":993},"Topics",[994,999,1004,1009,1014,1018,1023,1028],{"text":995,"config":996},"CICD",{"href":997,"dataGaName":998,"dataGaLocation":917},"/topics/ci-cd/","cicd",{"text":1000,"config":1001},"GitOps",{"href":1002,"dataGaName":1003,"dataGaLocation":917},"/topics/gitops/","gitops",{"text":1005,"config":1006},"DevOps",{"href":1007,"dataGaName":1008,"dataGaLocation":917},"/topics/devops/","devops",{"text":1010,"config":1011},"Version Control",{"href":1012,"dataGaName":1013,"dataGaLocation":917},"/topics/version-control/","version control",{"text":470,"config":1015},{"href":1016,"dataGaName":1017,"dataGaLocation":917},"/topics/devsecops/","devsecops",{"text":1019,"config":1020},"Cloud Native",{"href":1021,"dataGaName":1022,"dataGaLocation":917},"/topics/cloud-native/","cloud native",{"text":1024,"config":1025},"AI for Coding",{"href":1026,"dataGaName":1027,"dataGaLocation":917},"/topics/devops/ai-for-coding/","ai for coding",{"text":1029,"config":1030},"Agentic AI",{"href":1031,"dataGaName":1032,"dataGaLocation":917},"/topics/agentic-ai/","agentic ai",{"title":1034,"links":1035},"Solutions",[1036,1038,1040,1045,1049,1052,1056,1059,1061,1064,1067,1072],{"text":569,"config":1037},{"href":564,"dataGaName":569,"dataGaLocation":917},{"text":558,"config":1039},{"href":541,"dataGaName":542,"dataGaLocation":917},{"text":1041,"config":1042},"Agile development",{"href":1043,"dataGaName":1044,"dataGaLocation":917},"/solutions/agile-delivery/","agile delivery",{"text":1046,"config":1047},"SCM",{"href":554,"dataGaName":1048,"dataGaLocation":917},"source code management",{"text":995,"config":1050},{"href":547,"dataGaName":1051,"dataGaLocation":917},"continuous integration & delivery",{"text":1053,"config":1054},"Value stream management",{"href":597,"dataGaName":1055,"dataGaLocation":917},"value stream management",{"text":1000,"config":1057},{"href":1058,"dataGaName":1003,"dataGaLocation":917},"/solutions/gitops/",{"text":607,"config":1060},{"href":610,"dataGaName":611,"dataGaLocation":917},{"text":1062,"config":1063},"Small business",{"href":616,"dataGaName":617,"dataGaLocation":917},{"text":1065,"config":1066},"Public sector",{"href":622,"dataGaName":623,"dataGaLocation":917},{"text":1068,"config":1069},"Education",{"href":1070,"dataGaName":1071,"dataGaLocation":917},"/solutions/education/","education",{"text":1073,"config":1074},"Financial services",{"href":1075,"dataGaName":1076,"dataGaLocation":917},"/solutions/finance/","financial services",{"title":630,"links":1078},[1079,1081,1083,1085,1088,1090,1093,1095,1097,1099,1101,1103,1105,1107],{"text":643,"config":1080},{"href":645,"dataGaName":646,"dataGaLocation":917},{"text":648,"config":1082},{"href":650,"dataGaName":651,"dataGaLocation":917},{"text":653,"config":1084},{"href":655,"dataGaName":656,"dataGaLocation":917},{"text":658,"config":1086},{"href":660,"dataGaName":1087,"dataGaLocation":917},"docs",{"text":680,"config":1089},{"href":682,"dataGaName":683,"dataGaLocation":917},{"text":1091,"config":1092},"What's new",{"href":739,"dataGaName":740,"dataGaLocation":917},{"text":675,"config":1094},{"href":677,"dataGaName":678,"dataGaLocation":917},{"text":694,"config":1096},{"href":696,"dataGaName":697,"dataGaLocation":917},{"text":702,"config":1098},{"href":704,"dataGaName":705,"dataGaLocation":917},{"text":707,"config":1100},{"href":709,"dataGaName":710,"dataGaLocation":917},{"text":712,"config":1102},{"href":714,"dataGaName":715,"dataGaLocation":917},{"text":717,"config":1104},{"href":719,"dataGaName":720,"dataGaLocation":917},{"text":722,"config":1106},{"href":724,"dataGaName":725,"dataGaLocation":917},{"text":727,"config":1108},{"href":729,"dataGaName":468,"dataGaLocation":917},{"title":742,"links":1110},[1111,1113,1115,1117,1119,1121,1125,1130,1132,1134,1136],{"text":750,"config":1112},{"href":752,"dataGaName":744,"dataGaLocation":917},{"text":755,"config":1114},{"href":757,"dataGaName":758,"dataGaLocation":917},{"text":763,"config":1116},{"href":765,"dataGaName":766,"dataGaLocation":917},{"text":768,"config":1118},{"href":770,"dataGaName":771,"dataGaLocation":917},{"text":773,"config":1120},{"href":775,"dataGaName":776,"dataGaLocation":917},{"text":1122,"config":1123},"Sustainability",{"href":1124,"dataGaName":1122,"dataGaLocation":917},"/sustainability/",{"text":1126,"config":1127},"Diversity, inclusion and belonging (DIB)",{"href":1128,"dataGaName":1129,"dataGaLocation":917},"/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":778,"config":1131},{"href":780,"dataGaName":781,"dataGaLocation":917},{"text":788,"config":1133},{"href":790,"dataGaName":791,"dataGaLocation":917},{"text":793,"config":1135},{"href":795,"dataGaName":796,"dataGaLocation":917},{"text":1137,"config":1138},"Modern Slavery Transparency Statement",{"href":1139,"dataGaName":1140,"dataGaLocation":917},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":1142},[1143,1146,1149],{"text":1144,"config":1145},"Terms",{"href":969,"dataGaName":970,"dataGaLocation":917},{"text":1147,"config":1148},"Cookies",{"dataGaName":979,"dataGaLocation":917,"id":980,"isOneTrustButton":281},{"text":1150,"config":1151},"Privacy",{"href":974,"dataGaName":975,"dataGaLocation":917},[1153],{"id":1154,"title":7,"body":454,"config":1155,"content":1157,"description":454,"extension":1161,"meta":1162,"navigation":281,"path":1163,"seo":1164,"stem":1165,"__hash__":1166},"blogAuthors/en-us/blog/authors/fernando-diaz.yml",{"template":1156},"BlogAuthor",{"name":7,"config":1158},{"headshot":1159,"ctfId":1160},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749659556/Blog/Author%20Headshots/fern_diaz.png","fjdiaz","yml",{},"/en-us/blog/authors/fernando-diaz",{},"en-us/blog/authors/fernando-diaz","lxRJIOydP4_yzYZvsPcuQevP9AYAKREF7i8QmmdnOWc",[1168,1176,1184],{"title":1169,"description":1170,"heroImage":1171,"category":450,"date":1172,"authors":1173,"slug":1175,"externalUrl":454},"How GitLab tracks vulnerabilities through refactors and reformatting","Learn how GitLab's improved Scope+Offset fingerprinting keeps vulnerability tracking stable across comments, blank lines, and reformatting.","https://res.cloudinary.com/about-gitlab-com/image/upload/v1759320418/xjmqcozxzt4frx0hori3.png","2026-08-12",[1174],"Julian Thome","improved-scope-offset-fingerprinting",{"title":1177,"description":1178,"heroImage":1171,"category":450,"date":1179,"authors":1180,"slug":1183,"externalUrl":454},"GitLab Secrets Manager adds ESO, Terraform, API support","Simplify credential management across your stack. GitLab Secrets Manager provides secure retrieval in Kubernetes, Terraform, and external workflows.","2026-08-06",[1181,1182],"Erick Bajao","Joe Randazzo","gitlab-secrets-manager-add-eso-terraform-api-support",{"title":1185,"description":1186,"heroImage":1187,"category":450,"date":1188,"authors":1189,"slug":1191,"externalUrl":454},"Secure every commit to production with Claude and GitLab","Claude Security catches vulnerabilities inside a coding session. GitLab picks up from there, scanning, enforcing policy, and producing audit evidence for the software lifecycle. ","https://res.cloudinary.com/about-gitlab-com/image/upload/v1756122536/akivvcnafog9c4dhhzkp.png","2026-08-03",[1190],"Alisa Ho","claude-security-and-gitlab",{"promotions":1193},[1194,1208,1220,1231],{"id":1195,"categories":1196,"header":1198,"text":1199,"button":1200,"image":1205},"ai-modernization",[1197],"ai","Is AI achieving its promise at scale?","Quiz will take 5 minutes or less",{"text":1201,"config":1202},"Get your AI maturity score",{"href":1203,"dataGaName":1204,"dataGaLocation":683},"/assessments/ai-modernization-assessment/","modernization assessment",{"config":1206},{"src":1207},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/qix0m7kwnd8x2fh1zq49.png",{"id":1209,"categories":1210,"header":1212,"text":1199,"button":1213,"image":1217},"devops-modernization",[1211,1017],"product","Are you just managing tools or shipping innovation?",{"text":1214,"config":1215},"Get your DevOps maturity score",{"href":1216,"dataGaName":1204,"dataGaLocation":683},"/assessments/devops-modernization-assessment/",{"config":1218},{"src":1219},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138785/eg818fmakweyuznttgid.png",{"id":1221,"categories":1222,"header":1223,"text":1199,"button":1224,"image":1228},"security-modernization",[450],"Are you trading speed for security?",{"text":1225,"config":1226},"Get your security maturity score",{"href":1227,"dataGaName":1204,"dataGaLocation":683},"/assessments/security-modernization-assessment/",{"config":1229},{"src":1230},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/p4pbqd9nnjejg5ds6mdk.png",{"id":1232,"paths":1233,"header":1236,"text":1237,"button":1238,"image":1243},"github-azure-migration",[1234,1235],"migration-from-azure-devops-to-gitlab","integrating-azure-devops-scm-and-gitlab","Is your team ready for GitHub's Azure move?","GitHub is already rebuilding around Azure. Find out what it means for you.",{"text":1239,"config":1240},"See how GitLab compares to GitHub",{"href":1241,"dataGaName":1242,"dataGaLocation":683},"/compare/gitlab-vs-github/github-azure-migration/","github azure migration",{"config":1244},{"src":1219},{"header":1246,"blurb":1247,"button":1248,"secondaryButton":1253},"Start building faster today","See what your team can do with the intelligent orchestration platform for DevSecOps.\n",{"text":1249,"config":1250},"Get your free trial",{"href":1251,"dataGaName":484,"dataGaLocation":1252},"https://gitlab.com/-/trial_registrations/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/","feature",{"text":955,"config":1254},{"href":807,"dataGaName":489,"dataGaLocation":1252},1786803768417]