
We developed, tested and open sourced a new tool to analyze program dependencies and protect the supply chain.

DevSecOps is about more than shifting security testing to developers. Can you secure your software development end-to-end?

As usual, we’re creating our own path in how we handle our threat modeling, approaching development both iteratively and collaboratively, and seriously shifting left with our framework and processes.

Our security researcher takes a look at Gitpod and finds some access tokens under the carpet.

Out of an abundance of caution we’ve rotated the impacted keys and tokens.

We know GitLab is a complete open source DevOps platform, but can it improve your hack? We chat with three bug bounty hunters to find out.
All fields required