[{"data":1,"prerenderedAt":1242},["ShallowReactive",2],{"/blog/what-the-digital-operational-resilience-act-means-for-banks":3,"navigation-en-us":447,"banner-en-us":875,"footer-en-us":885,"blog-post-authors-en-us-Joshua Carroll|Allie Holland":1127,"blog-related-posts-en-us-what-the-digital-operational-resilience-act-means-for-banks":1154,"blog-promotions-en-us":1179,"next-steps-en-us":1232},{"id":4,"title":5,"authors":6,"body":9,"category":425,"date":426,"description":427,"extension":428,"externalUrl":429,"faq":429,"featured":430,"heroImage":431,"meta":432,"navigation":433,"path":434,"seo":435,"slug":439,"stem":440,"tags":441,"template":445,"updatedDate":429,"__hash__":446},"blogPosts/en-us/blog/what-the-digital-operational-resilience-act-means-for-banks.md","What the Digital Operational Resilience Act means for banks",[7,8],"Joshua Carroll","Allie Holland",{"type":10,"value":11,"toc":416},"minimark",[12,29,34,37,41,44,91,94,102,106,109,147,151,165,373,376,389,393],[13,14,15,16,22,23,28],"p",{},"Developers play a critical role in ensuring banks remain competitive and compliant. One framework gaining significant attention is DORA. If you’re thinking of the ",[17,18,21],"a",{"href":19,"rel":20},"https://docs.gitlab.com/user/analytics/dora_metrics/",[],"DevOps Research and Assessment (DORA) metrics",", this is something different. The ",[17,24,27],{"href":25,"rel":26},"https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en",[],"Digital Operational Resilience Act"," is a new regulatory framework focused on safeguarding financial institutions against digital disruptions. For developers, understanding DORA regulations is not just a regulatory necessity; it’s an opportunity to drive innovation and enhance the overall stability of their organizations.",[30,31,33],"h2",{"id":32},"what-is-dora-regulation","What is DORA regulation?",[13,35,36],{},"The Digital Operational Resilience Act (DORA) is a legislative framework introduced by the European Union to strengthen the operational resilience of financial institutions. DORA aims to ensure that banks and other financial services providers can withstand, respond to, and recover from all types of information and communication technology (ICT) related disruptions and threats. DORA outlines specific requirements for risk management, incident reporting, testing, and the overall governance of digital operations.",[30,38,40],{"id":39},"core-requirements-of-dora","Core requirements of DORA",[13,42,43],{},"DORA introduces several critical requirements for financial institutions to ensure they can maintain operational continuity, including:",[45,46,47,61,67,79],"ol",{},[48,49,50,54,55,60],"li",{},[51,52,53],"strong",{},"Risk management:"," Organizations must establish systems to identify, assess, and manage risks related to their digital operations. DORA fundamentally redefines the landscape of ICT risk management by placing accountability at the executive level. Detailed in ",[17,56,59],{"href":57,"rel":58},"https://www.digital-operational-resilience-act.com/Article_5.html",[],"Article 5",", the management body of an organization is now entrusted with the ultimate responsibility for overseeing ICT risk management. This includes conducting regular risk assessments and implementing strategies to mitigate identified vulnerabilities.",[48,62,63,66],{},[51,64,65],{},"Regular testing:"," Financial institutions are required to conduct systematic testing of their ICT systems to ensure they can handle potential disruptions effectively. This includes stress testing, scenario analysis, and recovery simulations to evaluate the resilience of their operations.",[48,68,69,72,73,78],{},[51,70,71],{},"Incident reporting:"," Significant ICT-related incidents must be reported to regulators within specified timeframes. This requirement enhances oversight and allows regulators to coordinate responses across the financial sector, ensuring a unified approach to managing crises. The most recent ",[17,74,77],{"href":75,"rel":76},"https://www.eba.europa.eu/sites/default/files/2023-12/ecc72f1c-c68a-4e64-97dd-47470117c3ae/JC%202023%2070%20-%20%20CP%20on%20draft%20RTS%20and%20ITS%20on%20major%20incident%20reporting%20under%20DORA.pdf",[],"Regulatory Technical Standards"," proposes time limits for reporting of the initial notification of four hours after classification and 24 hours after detection of the incident, 72 hours for reporting of the intermediate report, and one month for the reporting of the final report.",[48,80,81,84,85,90],{},[51,82,83],{},"Third-party risk management:"," DORA also focuses on managing risks associated with outsourcing services to third-party providers. Organizations must ensure that their partners adhere to the same stringent standards, conducting due diligence and regular assessments of third-party performance. One of the biggest shifts for a bank is oftentimes centered around the establishment of exit strategies, detailed in ",[17,86,89],{"href":87,"rel":88},"https://www.digital-operational-resilience-act.com/Article_28.html",[],"Article 28",".",[13,92,93],{},"Organizations need to prepare for scenarios where a third-party provider can no longer meet their operational needs or compliance obligations. This proactive approach ensures continuity and minimizes disruption in critical services. GitLab offers a distinct advantage in this area, as our platform is cloud-agnostic. This flexibility allows organizations to easily adapt their operations and transition between service providers as needed, simplifying the implementation of effective exit strategies.",[13,95,96,97,90],{},"For those who are interested in learning a bit more about the specifics listed above, the formal regulation documentation can be found ",[17,98,101],{"href":99,"rel":100},"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554",[],"here",[30,103,105],{"id":104},"why-dora-matters-to-developers","Why DORA matters to developers",[13,107,108],{},"DORA is important for developers to understand for the following reasons:",[45,110,111,123,129,135,141],{},[48,112,113,116,117,122],{},[51,114,115],{},"Enhanced security posture:"," For developers, DORA emphasizes the importance of robust cybersecurity measures. As cyber threats continue to evolve, being part of an organization that prioritizes security means you’ll need to build applications with security in mind from the beginning, with a shift ",[17,118,121],{"href":119,"rel":120},"https://www.youtube.com/watch?v=XnYstHObqlA",[],"security left mindset",". Compliance with DORA requires implementing best practices in secure coding, conducting regular vulnerability assessments, and ensuring that security controls are integrated into the software development lifecycle.",[48,124,125,128],{},[51,126,127],{},"Focus on resilience:"," DORA requires banks to have clear strategies for operational resilience. Developers must now design systems that go beyond surface level functionality, building applications that can withstand failures and protect against disruptions. Having a clear understanding of DORA can guide you in architecting applications that can seamlessly handle disruptions, whether from a technical failure or an external threat.",[48,130,131,134],{},[51,132,133],{},"Collaboration and cross-functional teams:"," Implementing DORA effectively requires a collaborative approach, which could pose a challenge in siloed banking structures. Developers will need to work closely with cybersecurity teams, risk management, and compliance officers.",[48,136,137,140],{},[51,138,139],{},"Agility in incident response:"," DORA mandates that organizations report and respond to incidents efficiently. Developers must be equipped to quickly address vulnerabilities and deploy fixes.",[48,142,143,146],{},[51,144,145],{},"Continuous improvement culture:"," DORA encourages a culture of continuous improvement and testing. This requires the adoption of practices like chaos engineering and regular stress testing of applications to ensure they can handle unexpected scenarios. Embracing these methodologies will not only help meet regulatory requirements but also improve the overall quality and reliability of the software that is built.",[30,148,150],{"id":149},"gitlabs-role-in-dora-compliance","GitLab's role in DORA compliance",[13,152,153,154,159,160,90],{},"GitLab is prepared to help financial institutions meet DORA’s stringent requirements. With ",[17,155,158],{"href":156,"rel":157},"https://about.gitlab.com/topics/ci-cd/shift-left-devops/",[],"security built into the earliest stages of deployment pipelines",", GitLab is strategically positioned to equip organizations with software that is ",[17,161,164],{"href":162,"rel":163},"https://about.gitlab.com/blog/secure-by-design-principles-meet-devsecops-innovation-in-gitlab-17/",[],"Secure by Design",[166,167,168,212,268,306],"ul",{},[48,169,170,173,174,179,180,185,186,189,190,193,194,199,200,205,206,189,208,211],{},[51,171,172],{},"Robust risk management:"," GitLab’s built-in tools enable organizations to identify, assess, and manage risk across their digital landscape. By utilizing features like ",[17,175,178],{"href":176,"rel":177},"https://docs.gitlab.com/user/project/issues/",[],"issue tracking"," and ",[17,181,184],{"href":182,"rel":183},"https://docs.gitlab.com/user/project/merge_requests/",[],"merge requests",", teams can collaboratively manage and document risks throughout the software development lifecycle. GitLab provides several tools that enable organizations to manage these requirements effectively:",[187,188],"br",{},"\n- ",[51,191,192],{},"Audit logs and compliance dashboards:"," GitLab's ",[17,195,198],{"href":196,"rel":197},"https://docs.gitlab.com/user/compliance/audit_events/",[],"audit logs"," capture all activities within the platform, giving financial institutions a full history of changes made to code, configurations, and infrastructure. These logs allow compliance teams to review user actions and detect irregularities that could pose risks. Additionally, GitLab’s ",[17,201,204],{"href":202,"rel":203},"https://docs.gitlab.com/user/compliance/compliance_center/",[],"compliance dashboard"," provides real-time visibility into which projects comply with established policies, making it easier to manage large-scale governance.",[187,207],{},[51,209,210],{},"Custom compliance frameworks:"," GitLab allows organizations to create custom compliance frameworks that are tailored to an organization's regulatory requirements and geographical regions. These frameworks ensure consistent enforcement of security and operational standards, meeting DORA’s systematic risk management objectives.",[48,213,214,217,218,223,224,258,260,261,263],{},[51,215,216],{},"Comprehensive application security testing:"," Security vulnerabilities pose significant regulatory, financial, and reputational risks. GitLab addresses these challenges by building security testing directly into its CI/CD pipelines, ensuring vulnerabilities are detected and mitigated before deployment. This approach leverages multiple ",[17,219,222],{"href":220,"rel":221},"https://about.gitlab.com/stages-devops-lifecycle/secure/",[],"testing methodologies",":",[166,225,226,234,242,250],{},[48,227,228,233],{},[17,229,232],{"href":230,"rel":231},"https://docs.gitlab.com/user/application_security/sast/",[],"Static Application Security Testing (SAST)",": Analyzes source code for security vulnerabilities.",[48,235,236,241],{},[17,237,240],{"href":238,"rel":239},"https://docs.gitlab.com/user/application_security/dast/",[],"Dynamic Application Security Testing (DAST)",": Tests running applications for security weaknesses.",[48,243,244,249],{},[17,245,248],{"href":246,"rel":247},"https://docs.gitlab.com/user/application_security/secret_detection/",[],"Secret Detection",": Prevents sensitive information from being exposed in code.",[48,251,252,257],{},[17,253,256],{"href":254,"rel":255},"https://docs.gitlab.com/user/application_security/coverage_fuzzing/",[],"Fuzz Testing",": Identifies potential security issues by testing with random inputs.",[187,259],{},"GitLab’s security tools run automated tests that scan for vulnerabilities in code, containers, and third-party dependencies. These features help organizations meet the DORA requirement to continuously test IT systems, providing peace of mind that potential vulnerabilities are addressed before they become operational risks.",[187,262],{},[264,265],"img",{"alt":266,"src":267},"GitLab features for DORA requirements in EU","https://res.cloudinary.com/about-gitlab-com/image/upload/v1750098160/Blog/Content%20Images/Blog/Content%20Images/image1_aHR0cHM6_1750098160209.png",[48,269,270,273,274,279,280,285,286,291,292],{},[51,271,272],{},"Efficient incident reporting:"," GitLab’s ",[17,275,278],{"href":276,"rel":277},"https://docs.gitlab.com/topics/plan_and_track/",[],"project management capabilities"," enable teams to effectively log and track significant ICT-related incidents. This centralized documentation, combined with ",[17,281,284],{"href":282,"rel":283},"https://docs.gitlab.com/user/application_security/continuous_vulnerability_scanning/",[],"continuous vulnerability scanning",", facilitates timely reporting to regulators, enhances visibility, and supports compliance with DORA's incident reporting requirements.\n",[17,287,290],{"href":288,"rel":289},"https://docs.gitlab.com/operations/incident_management/incidents/#:~:text=The%20incident%20summary%20can%20be,displays%20them%20below%20the%20summary.",[],"GitLab's incident management features"," streamline the workflow of remediation, making it easier for teams to identify, trace, and act on incidents as they arise.",[166,293,294,297],{},[48,295,296],{},"Incident management tools: GitLab includes built-in tools for managing incidents, serving as a centralized record for teams to report, assess, and mitigate issues effectively. Users can create incident records, assign ownership, and document the investigation and resolution process. This centralization not only streamlines incident management but also enables teams to trace back and determine accountability for each incident. By facilitating clear ownership and structured workflows, GitLab positions organizations to effectively meet DORA’s requirements for effective incident response plans.",[48,298,299,300,305],{},"Real-time alerts and monitoring integrations: By integrating with monitoring tools such as ",[17,301,304],{"href":302,"rel":303},"https://prometheus.io/",[],"Prometheus"," and Grafana, GitLab allows financial institutions to receive real-time alerts when issues arise. These alerts can trigger automated incident responses, helping teams address potential threats before they escalate, in line with DORA’s emphasis on quick reaction times.",[48,307,308,310,311,370,372],{},[51,309,83],{}," GitLab enables organizations to work closely with third-party providers, ensuring they adhere to the same rigorous standards required by the industry. The platform provides both technical controls and governance features to manage third-party risks:",[166,312,313,342],{},[48,314,315,316],{},"Technical Controls",[166,317,318,326,334],{},[48,319,320,325],{},[17,321,324],{"href":322,"rel":323},"https://docs.gitlab.com/user/application_security/dependency_scanning/",[],"Dependency Scanning",": Automatically detects vulnerabilities in third-party libraries and open-source components",[48,327,328,333],{},[17,329,332],{"href":330,"rel":331},"https://about.gitlab.com/blog/reduce-supply-chain-risk-with-smarter-vulnerability-prioritization/",[],"Software Composition Analysis",": Provides detailed inventory and security status of all external dependencies",[48,335,336,341],{},[17,337,340],{"href":338,"rel":339},"https://docs.gitlab.com/user/application_security/container_scanning/",[],"Container Scanning",": Identifies vulnerabilities in third-party container images",[48,343,344,345],{},"Governance Features",[166,346,347,355,363],{},[48,348,349,354],{},[17,350,353],{"href":351,"rel":352},"https://docs.gitlab.com/user/application_security/policies/",[],"Policy Enforcement",": Automatically enforce security policies for external code and components",[48,356,357,362],{},[17,358,361],{"href":359,"rel":360},"https://docs.gitlab.com/api/project_integrations/",[],"Integration Controls",": GitLab's API-first approach ensures secure and monitored integration with external systems",[48,364,365,369],{},[17,366,368],{"href":196,"rel":367},[],"Audit Trails",": Maintain comprehensive logs of all third-party component usage and changes",[187,371],{},"These capabilities help organizations meet DORA's requirements for third-party risk management while maintaining operational efficiency.",[13,374,375],{},"The EU’s DORA regulations present new challenges for financial institutions, requiring them to enhance their governance, cybersecurity, and resilience frameworks. GitLab offers powerful features that address the key pillars of DORA, from incident management to cybersecurity testing and third-party risk management. By integrating GitLab into operational processes, financial institutions can streamline their compliance efforts, reduce risks, and ensure that they meet regulatory requirements with greater efficiency. GitLab provides a solid foundation for organizations seeking to stay ahead of the evolving regulatory landscape while maintaining strong security and operational resilience.",[377,378,379],"blockquote",{},[380,381,383,388],"h4",{"id":382},"reach-out-to-learn-more-about-how-gitlab-can-help-meet-your-regulatory-challenges",[17,384,387],{"href":385,"rel":386},"https://about.gitlab.com/solutions/finance/",[],"Reach out"," to learn more about how GitLab can help meet your regulatory challenges.",[30,390,392],{"id":391},"read-more","Read more",[166,394,395,402,409],{},[48,396,397],{},[17,398,401],{"href":399,"rel":400},"https://about.gitlab.com/blog/gitlab-supports-banks-in-navigating-regulatory-challenges/",[],"GitLab supports banks in navigating regulatory challenges",[48,403,404],{},[17,405,408],{"href":406,"rel":407},"https://about.gitlab.com/blog/meet-regulatory-standards-with-gitlab/",[],"Meet regulatory standards with GitLab security and compliance",[48,410,411],{},[17,412,415],{"href":413,"rel":414},"https://about.gitlab.com/blog/ensuring-compliance/",[],"How to ensure separation of duties and enforce compliance with GitLab",{"title":417,"searchDepth":418,"depth":418,"links":419},"",2,[420,421,422,423,424],{"id":32,"depth":418,"text":33},{"id":39,"depth":418,"text":40},{"id":104,"depth":418,"text":105},{"id":149,"depth":418,"text":150},{"id":391,"depth":418,"text":392},"security","2025-01-15","Find out why financial institutions need to understand the DORA legislative framework introduced in the European Union to strengthen operational resilience.","md",null,false,"https://res.cloudinary.com/about-gitlab-com/image/upload/v1750098149/Blog/Hero%20Images/Blog/Hero%20Images/blog-image-template-1800x945%20%284%29_3LZkiDjHLjhqEkvOvBsVKp_1750098149751.png",{},true,"/en-us/blog/what-the-digital-operational-resilience-act-means-for-banks",{"title":5,"description":427,"ogTitle":5,"ogDescription":427,"noIndex":430,"ogImage":431,"ogUrl":436,"ogSiteName":437,"ogType":438,"canonicalUrls":436},"https://about.gitlab.com/blog/what-the-digital-operational-resilience-act-means-for-banks","https://about.gitlab.com","article","what-the-digital-operational-resilience-act-means-for-banks","en-us/blog/what-the-digital-operational-resilience-act-means-for-banks",[442,425,443,444],"financial services","DevSecOps platform","DevSecOps","BlogPost","pnzFENu-uw1NWQpyvccqwOeQtzrOIa09gB4TTRwIBbQ",{"logo":448,"freeTrial":453,"sales":458,"login":463,"items":468,"search":795,"minimal":826,"duo":845,"switchNav":854,"pricingDeployment":865},{"config":449},{"href":450,"dataGaName":451,"dataGaLocation":452},"/","gitlab logo","header",{"text":454,"config":455},"Get free trial",{"href":456,"dataGaName":457,"dataGaLocation":452},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com&glm_content=default-saas-trial/","free trial",{"text":459,"config":460},"Request a demo",{"href":461,"dataGaName":462,"dataGaLocation":452},"/sales/?contact-topic=request-demo","sales",{"text":464,"config":465},"Sign in",{"href":466,"dataGaName":467,"dataGaLocation":452},"https://gitlab.com/users/sign_in/","sign in",[469,498,598,603,717,773],{"text":470,"config":471,"menu":473},"Platform",{"dataNavLevelOne":472},"platform",{"type":474,"columns":475},"cards",[476,482,490],{"title":470,"description":477,"link":478},"The intelligent orchestration platform for DevSecOps",{"text":479,"config":480},"Explore our Platform",{"href":481,"dataGaName":472,"dataGaLocation":452},"/platform/",{"title":483,"description":484,"link":485},"GitLab Duo Agent Platform","Agentic AI for the entire software lifecycle",{"text":486,"config":487},"Meet GitLab Duo",{"href":488,"dataGaName":489,"dataGaLocation":452},"/gitlab-duo-agent-platform/","gitlab duo agent platform",{"title":491,"description":492,"link":493},"Why GitLab","See the top reasons enterprises choose GitLab",{"text":494,"config":495},"Learn more",{"href":496,"dataGaName":497,"dataGaLocation":452},"/why-gitlab/","why gitlab",{"text":499,"left":433,"config":500,"menu":502},"Product",{"dataNavLevelOne":501},"solutions",{"type":503,"link":504,"columns":508,"feature":577},"lists",{"text":505,"config":506},"View all Solutions",{"href":507,"dataGaName":501,"dataGaLocation":452},"/solutions/",[509,533,556],{"title":510,"description":511,"link":512,"items":517},"Automation","CI/CD and automation to accelerate deployment",{"config":513},{"icon":514,"href":515,"dataGaName":516,"dataGaLocation":452},"AutomatedCodeAlt","/solutions/delivery-automation/","automated software delivery",[518,522,525,529],{"text":519,"config":520},"CI/CD",{"href":521,"dataGaLocation":452,"dataGaName":519},"/solutions/continuous-integration/",{"text":483,"config":523},{"href":488,"dataGaLocation":452,"dataGaName":524},"gitlab duo agent platform - product menu",{"text":526,"config":527},"Source Code Management",{"href":528,"dataGaLocation":452,"dataGaName":526},"/solutions/source-code-management/",{"text":530,"config":531},"Automated Software Delivery",{"href":515,"dataGaLocation":452,"dataGaName":532},"Automated software delivery",{"title":534,"description":535,"link":536,"items":541},"Security","Deliver code faster without compromising security",{"config":537},{"href":538,"dataGaName":539,"dataGaLocation":452,"icon":540},"/solutions/application-security-testing/","security and compliance","ShieldCheckLight",[542,546,551],{"text":543,"config":544},"Application Security Testing",{"href":538,"dataGaName":545,"dataGaLocation":452},"Application security testing",{"text":547,"config":548},"Software Supply Chain Security",{"href":549,"dataGaLocation":452,"dataGaName":550},"/solutions/supply-chain/","Software supply chain security",{"text":552,"config":553},"Software Compliance",{"href":554,"dataGaName":555,"dataGaLocation":452},"/solutions/software-compliance/","software compliance",{"title":557,"link":558,"items":563},"Measurement",{"config":559},{"icon":560,"href":561,"dataGaName":562,"dataGaLocation":452},"DigitalTransformation","/solutions/visibility-measurement/","visibility and measurement",[564,568,572],{"text":565,"config":566},"Visibility & Measurement",{"href":561,"dataGaLocation":452,"dataGaName":567},"Visibility and Measurement",{"text":569,"config":570},"Value Stream Management",{"href":571,"dataGaLocation":452,"dataGaName":569},"/solutions/value-stream-management/",{"text":573,"config":574},"Analytics & Insights",{"href":575,"dataGaLocation":452,"dataGaName":576},"/solutions/analytics-and-insights/","Analytics and insights",{"title":578,"type":503,"items":579},"GitLab for",[580,586,592],{"text":581,"config":582},"Enterprise",{"icon":583,"href":584,"dataGaLocation":452,"dataGaName":585},"Building","/enterprise/","enterprise",{"text":587,"config":588},"Small Business",{"icon":589,"href":590,"dataGaLocation":452,"dataGaName":591},"Work","/small-business/","small business",{"text":593,"config":594},"Public Sector",{"icon":595,"href":596,"dataGaLocation":452,"dataGaName":597},"Organization","/solutions/public-sector/","public sector",{"text":599,"config":600},"Pricing",{"href":601,"dataGaName":602,"dataGaLocation":452,"dataNavLevelOne":602},"/pricing/","pricing",{"text":604,"config":605,"menu":607},"Resources",{"dataNavLevelOne":606},"resources",{"type":503,"link":608,"columns":612,"feature":706},{"text":609,"config":610},"View all resources",{"href":611,"dataGaName":606,"dataGaLocation":452},"/resources/",[613,646,673],{"title":614,"items":615},"Getting started",[616,621,626,631,636,641],{"text":617,"config":618},"Install",{"href":619,"dataGaName":620,"dataGaLocation":452},"/install/","install",{"text":622,"config":623},"Quick start guides",{"href":624,"dataGaName":625,"dataGaLocation":452},"/get-started/","quick setup checklists",{"text":627,"config":628},"Learn",{"href":629,"dataGaLocation":452,"dataGaName":630},"https://university.gitlab.com/","learn",{"text":632,"config":633},"Product documentation",{"href":634,"dataGaName":635,"dataGaLocation":452},"https://docs.gitlab.com/","product documentation",{"text":637,"config":638},"Best practice videos",{"href":639,"dataGaName":640,"dataGaLocation":452},"/getting-started-videos/","best practice videos",{"text":642,"config":643},"Integrations",{"href":644,"dataGaName":645,"dataGaLocation":452},"/integrations/","integrations",{"title":647,"items":648},"Discover",[649,654,659,664,668],{"text":650,"config":651},"Customer success stories",{"href":652,"dataGaName":653,"dataGaLocation":452},"/customers/","customer success stories",{"text":655,"config":656},"Blog",{"href":657,"dataGaName":658,"dataGaLocation":452},"/blog/","blog",{"text":660,"config":661},"Demo Hub",{"href":662,"dataGaName":663,"dataGaLocation":452},"/demo-hub/","demo hub",{"text":665,"config":666},"The Source",{"href":667,"dataGaName":658,"dataGaLocation":452},"/the-source/",{"text":669,"config":670},"Remote",{"href":671,"dataGaName":672,"dataGaLocation":452},"https://handbook.gitlab.com/handbook/company/culture/all-remote/","remote",{"title":674,"items":675},"Connect",[676,681,686,691,696,701],{"text":677,"config":678},"GitLab Services",{"href":679,"dataGaName":680,"dataGaLocation":452},"/services/","services",{"text":682,"config":683},"Contribute",{"href":684,"dataGaName":685,"dataGaLocation":452},"https://contributors.gitlab.com","contribute",{"text":687,"config":688},"Community",{"href":689,"dataGaName":690,"dataGaLocation":452},"/community/","community",{"text":692,"config":693},"Forum",{"href":694,"dataGaName":695,"dataGaLocation":452},"https://forum.gitlab.com/","forum",{"text":697,"config":698},"Events",{"href":699,"dataGaName":700,"dataGaLocation":452},"/events/","events",{"text":702,"config":703},"Partners",{"href":704,"dataGaName":705,"dataGaLocation":452},"/partners/","partners",{"config":707,"title":710,"text":711,"link":712},{"background":708,"textColor":709},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1777322348/qpq8yrgn8knii57omj0c.png')","#000","What’s new in GitLab","Stay updated with our latest features and improvements.",{"text":713,"config":714},"Read the latest",{"href":715,"dataGaName":716,"dataGaLocation":452},"/whats-new/","whats new",{"text":718,"config":719,"menu":721},"Company",{"dataNavLevelOne":720},"company",{"type":503,"columns":722},[723],{"items":724},[725,730,736,738,743,748,753,758,763,768],{"text":726,"config":727},"About",{"href":728,"dataGaName":729,"dataGaLocation":452},"/company/","about",{"text":731,"config":732,"footerGa":735},"Jobs",{"href":733,"dataGaName":734,"dataGaLocation":452},"/jobs/","jobs",{"dataGaName":734},{"text":697,"config":737},{"href":699,"dataGaName":700,"dataGaLocation":452},{"text":739,"config":740},"Leadership",{"href":741,"dataGaName":742,"dataGaLocation":452},"/company/team/e-group/","leadership",{"text":744,"config":745},"Handbook",{"href":746,"dataGaName":747,"dataGaLocation":452},"https://handbook.gitlab.com/","handbook",{"text":749,"config":750},"Investor relations",{"href":751,"dataGaName":752,"dataGaLocation":452},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":754,"config":755},"Trust Center",{"href":756,"dataGaName":757,"dataGaLocation":452},"/security/","trust center",{"text":759,"config":760},"AI Transparency Center",{"href":761,"dataGaName":762,"dataGaLocation":452},"/ai-transparency-center/","ai transparency center",{"text":764,"config":765},"Newsletter",{"href":766,"dataGaName":767,"dataGaLocation":452},"/company/contact/#contact-forms","newsletter",{"text":769,"config":770},"Press",{"href":771,"dataGaName":772,"dataGaLocation":452},"/press/","press",{"text":774,"config":775,"menu":776},"Contact us",{"dataNavLevelOne":720},{"type":503,"columns":777},[778],{"items":779},[780,785,790],{"text":781,"config":782},"Talk to sales",{"href":783,"dataGaName":784,"dataGaLocation":452},"/sales/","talk to sales",{"text":786,"config":787},"Support portal",{"href":788,"dataGaName":789,"dataGaLocation":452},"https://support.gitlab.com/hc/en-us","support portal",{"text":791,"config":792},"Customer portal",{"href":793,"dataGaName":794,"dataGaLocation":452},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":796,"login":797,"suggestions":804},"Close",{"text":798,"link":799},"To search repositories and projects, login to",{"text":800,"config":801},"gitlab.com",{"href":466,"dataGaName":802,"dataGaLocation":803},"search login","search",{"text":805,"default":806},"Suggestions",[807,809,813,815,819,823],{"text":483,"config":808},{"href":488,"dataGaName":483,"dataGaLocation":803},{"text":810,"config":811},"Code Suggestions (AI)",{"href":812,"dataGaName":810,"dataGaLocation":803},"/solutions/code-suggestions/",{"text":519,"config":814},{"href":521,"dataGaName":519,"dataGaLocation":803},{"text":816,"config":817},"GitLab on AWS",{"href":818,"dataGaName":816,"dataGaLocation":803},"/partners/technology-partners/aws/",{"text":820,"config":821},"GitLab on Google Cloud",{"href":822,"dataGaName":820,"dataGaLocation":803},"/partners/technology-partners/google-cloud-platform/",{"text":824,"config":825},"Why GitLab?",{"href":496,"dataGaName":824,"dataGaLocation":803},{"freeTrial":827,"mobileIcon":832,"desktopIcon":837,"secondaryButton":840},{"text":828,"config":829},"Start free trial",{"href":830,"dataGaName":457,"dataGaLocation":831},"https://gitlab.com/-/trials/new/","nav",{"altText":833,"config":834},"Gitlab Icon",{"src":835,"dataGaName":836,"dataGaLocation":831},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":833,"config":838},{"src":839,"dataGaName":836,"dataGaLocation":831},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":841,"config":842},"Get Started",{"href":843,"dataGaName":844,"dataGaLocation":831},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/get-started/","get started",{"freeTrial":846,"mobileIcon":850,"desktopIcon":852},{"text":847,"config":848},"Learn more about GitLab Duo",{"href":488,"dataGaName":849,"dataGaLocation":831},"gitlab duo",{"altText":833,"config":851},{"src":835,"dataGaName":836,"dataGaLocation":831},{"altText":833,"config":853},{"src":839,"dataGaName":836,"dataGaLocation":831},{"button":855,"mobileIcon":860,"desktopIcon":862},{"text":856,"config":857},"/switch",{"href":858,"dataGaName":859,"dataGaLocation":831},"#contact","switch",{"altText":833,"config":861},{"src":835,"dataGaName":836,"dataGaLocation":831},{"altText":833,"config":863},{"src":864,"dataGaName":836,"dataGaLocation":831},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":866,"mobileIcon":871,"desktopIcon":873},{"text":867,"config":868},"Back to pricing",{"href":601,"dataGaName":869,"dataGaLocation":831,"icon":870},"back to pricing","GoBack",{"altText":833,"config":872},{"src":835,"dataGaName":836,"dataGaLocation":831},{"altText":833,"config":874},{"src":839,"dataGaName":836,"dataGaLocation":831},{"title":876,"titleMobile":877,"button":878,"config":883},"Duo Agent Platform delivers 400% ROI, per new Forrester Consulting study.","400% ROI: Forrester TEI for GitLab Duo",{"text":494,"config":879},{"href":880,"dataGaName":881,"dataGaLocation":882},"https://about.gitlab.com/blog/gitlab-duo-agent-platform-delivers-400-percent-roi/","forrester-tei-dap-banner","global-banner",{"layout":884,"disabled":430},"release",{"data":886},{"text":887,"source":888,"edit":894,"contribute":899,"config":904,"items":909,"minimal":1116},"Git is a trademark of Software Freedom Conservancy and our use of 'GitLab' is under license",{"text":889,"config":890},"View page source",{"href":891,"dataGaName":892,"dataGaLocation":893},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":895,"config":896},"Edit this page",{"href":897,"dataGaName":898,"dataGaLocation":893},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":900,"config":901},"Please contribute",{"href":902,"dataGaName":903,"dataGaLocation":893},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":905,"facebook":906,"youtube":907,"linkedin":908},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[910,957,1009,1052,1084],{"title":599,"links":911,"subMenu":926},[912,916,921],{"text":913,"config":914},"View plans",{"href":601,"dataGaName":915,"dataGaLocation":893},"view plans",{"text":917,"config":918},"Why Premium?",{"href":919,"dataGaName":920,"dataGaLocation":893},"/pricing/premium/","why premium",{"text":922,"config":923},"Why Ultimate?",{"href":924,"dataGaName":925,"dataGaLocation":893},"/pricing/ultimate/","why ultimate",[927],{"title":928,"links":929},"Contact Us",[930,933,935,937,942,947,952],{"text":931,"config":932},"Contact sales",{"href":783,"dataGaName":462,"dataGaLocation":893},{"text":786,"config":934},{"href":788,"dataGaName":789,"dataGaLocation":893},{"text":791,"config":936},{"href":793,"dataGaName":794,"dataGaLocation":893},{"text":938,"config":939},"Status",{"href":940,"dataGaName":941,"dataGaLocation":893},"https://status.gitlab.com/","status",{"text":943,"config":944},"Terms of use",{"href":945,"dataGaName":946,"dataGaLocation":893},"/terms/","terms of use",{"text":948,"config":949},"Privacy statement",{"href":950,"dataGaName":951,"dataGaLocation":893},"/privacy/","privacy statement",{"text":953,"config":954},"Cookie preferences",{"dataGaName":955,"dataGaLocation":893,"id":956,"isOneTrustButton":433},"cookie preferences","ot-sdk-btn",{"title":499,"links":958,"subMenu":966},[959,962],{"text":443,"config":960},{"href":481,"dataGaName":961,"dataGaLocation":893},"devsecops platform",{"text":963,"config":964},"AI-Assisted Development",{"href":488,"dataGaName":965,"dataGaLocation":893},"ai-assisted development",[967],{"title":968,"links":969},"Topics",[970,975,980,985,990,994,999,1004],{"text":971,"config":972},"CICD",{"href":973,"dataGaName":974,"dataGaLocation":893},"/topics/ci-cd/","cicd",{"text":976,"config":977},"GitOps",{"href":978,"dataGaName":979,"dataGaLocation":893},"/topics/gitops/","gitops",{"text":981,"config":982},"DevOps",{"href":983,"dataGaName":984,"dataGaLocation":893},"/topics/devops/","devops",{"text":986,"config":987},"Version Control",{"href":988,"dataGaName":989,"dataGaLocation":893},"/topics/version-control/","version control",{"text":444,"config":991},{"href":992,"dataGaName":993,"dataGaLocation":893},"/topics/devsecops/","devsecops",{"text":995,"config":996},"Cloud Native",{"href":997,"dataGaName":998,"dataGaLocation":893},"/topics/cloud-native/","cloud native",{"text":1000,"config":1001},"AI for Coding",{"href":1002,"dataGaName":1003,"dataGaLocation":893},"/topics/devops/ai-for-coding/","ai for coding",{"text":1005,"config":1006},"Agentic AI",{"href":1007,"dataGaName":1008,"dataGaLocation":893},"/topics/agentic-ai/","agentic ai",{"title":1010,"links":1011},"Solutions",[1012,1014,1016,1021,1025,1028,1032,1035,1037,1040,1043,1048],{"text":543,"config":1013},{"href":538,"dataGaName":543,"dataGaLocation":893},{"text":532,"config":1015},{"href":515,"dataGaName":516,"dataGaLocation":893},{"text":1017,"config":1018},"Agile development",{"href":1019,"dataGaName":1020,"dataGaLocation":893},"/solutions/agile-delivery/","agile delivery",{"text":1022,"config":1023},"SCM",{"href":528,"dataGaName":1024,"dataGaLocation":893},"source code management",{"text":971,"config":1026},{"href":521,"dataGaName":1027,"dataGaLocation":893},"continuous integration & delivery",{"text":1029,"config":1030},"Value stream management",{"href":571,"dataGaName":1031,"dataGaLocation":893},"value stream management",{"text":976,"config":1033},{"href":1034,"dataGaName":979,"dataGaLocation":893},"/solutions/gitops/",{"text":581,"config":1036},{"href":584,"dataGaName":585,"dataGaLocation":893},{"text":1038,"config":1039},"Small business",{"href":590,"dataGaName":591,"dataGaLocation":893},{"text":1041,"config":1042},"Public sector",{"href":596,"dataGaName":597,"dataGaLocation":893},{"text":1044,"config":1045},"Education",{"href":1046,"dataGaName":1047,"dataGaLocation":893},"/solutions/education/","education",{"text":1049,"config":1050},"Financial services",{"href":1051,"dataGaName":442,"dataGaLocation":893},"/solutions/finance/",{"title":604,"links":1053},[1054,1056,1058,1060,1063,1065,1068,1070,1072,1074,1076,1078,1080,1082],{"text":617,"config":1055},{"href":619,"dataGaName":620,"dataGaLocation":893},{"text":622,"config":1057},{"href":624,"dataGaName":625,"dataGaLocation":893},{"text":627,"config":1059},{"href":629,"dataGaName":630,"dataGaLocation":893},{"text":632,"config":1061},{"href":634,"dataGaName":1062,"dataGaLocation":893},"docs",{"text":655,"config":1064},{"href":657,"dataGaName":658,"dataGaLocation":893},{"text":1066,"config":1067},"What's new",{"href":715,"dataGaName":716,"dataGaLocation":893},{"text":650,"config":1069},{"href":652,"dataGaName":653,"dataGaLocation":893},{"text":669,"config":1071},{"href":671,"dataGaName":672,"dataGaLocation":893},{"text":677,"config":1073},{"href":679,"dataGaName":680,"dataGaLocation":893},{"text":682,"config":1075},{"href":684,"dataGaName":685,"dataGaLocation":893},{"text":687,"config":1077},{"href":689,"dataGaName":690,"dataGaLocation":893},{"text":692,"config":1079},{"href":694,"dataGaName":695,"dataGaLocation":893},{"text":697,"config":1081},{"href":699,"dataGaName":700,"dataGaLocation":893},{"text":702,"config":1083},{"href":704,"dataGaName":705,"dataGaLocation":893},{"title":718,"links":1085},[1086,1088,1090,1092,1094,1096,1100,1105,1107,1109,1111],{"text":726,"config":1087},{"href":728,"dataGaName":720,"dataGaLocation":893},{"text":731,"config":1089},{"href":733,"dataGaName":734,"dataGaLocation":893},{"text":739,"config":1091},{"href":741,"dataGaName":742,"dataGaLocation":893},{"text":744,"config":1093},{"href":746,"dataGaName":747,"dataGaLocation":893},{"text":749,"config":1095},{"href":751,"dataGaName":752,"dataGaLocation":893},{"text":1097,"config":1098},"Sustainability",{"href":1099,"dataGaName":1097,"dataGaLocation":893},"/sustainability/",{"text":1101,"config":1102},"Diversity, inclusion and belonging (DIB)",{"href":1103,"dataGaName":1104,"dataGaLocation":893},"/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":754,"config":1106},{"href":756,"dataGaName":757,"dataGaLocation":893},{"text":764,"config":1108},{"href":766,"dataGaName":767,"dataGaLocation":893},{"text":769,"config":1110},{"href":771,"dataGaName":772,"dataGaLocation":893},{"text":1112,"config":1113},"Modern Slavery Transparency Statement",{"href":1114,"dataGaName":1115,"dataGaLocation":893},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":1117},[1118,1121,1124],{"text":1119,"config":1120},"Terms",{"href":945,"dataGaName":946,"dataGaLocation":893},{"text":1122,"config":1123},"Cookies",{"dataGaName":955,"dataGaLocation":893,"id":956,"isOneTrustButton":433},{"text":1125,"config":1126},"Privacy",{"href":950,"dataGaName":951,"dataGaLocation":893},[1128,1142],{"id":1129,"title":7,"body":429,"config":1130,"content":1132,"description":429,"extension":1136,"meta":1137,"navigation":433,"path":1138,"seo":1139,"stem":1140,"__hash__":1141},"blogAuthors/en-us/blog/authors/joshua-carroll.yml",{"template":1131},"BlogAuthor",{"name":7,"config":1133},{"headshot":1134,"ctfId":1135},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749664952/Blog/Author%20Headshots/joshua_carroll_headshot.png","8HOTaXswBopyqMWFZMSv3","yml",{},"/en-us/blog/authors/joshua-carroll",{},"en-us/blog/authors/joshua-carroll","-HDdcU0XXWZSp6ZrHJVhFHAhJRoSqeUJo4_cJdSpL8w",{"id":1143,"title":8,"body":429,"config":1144,"content":1145,"description":429,"extension":1136,"meta":1149,"navigation":433,"path":1150,"seo":1151,"stem":1152,"__hash__":1153},"blogAuthors/en-us/blog/authors/allie-holland.yml",{"template":1131},{"name":8,"config":1146},{"headshot":1147,"ctfId":1148},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749664869/Blog/Author%20Headshots/allie_headshot.png","4Sc66Y8dwHEHwBNuJSh4Mv",{},"/en-us/blog/authors/allie-holland",{},"en-us/blog/authors/allie-holland","59cMmWMDNNqUZDd3obeHbXcM4_1LEVmHHI1IX9Ss4Fs",[1155,1163,1171],{"title":1156,"description":1157,"heroImage":1158,"category":425,"date":1159,"authors":1160,"slug":1162,"externalUrl":429},"How GitLab tracks vulnerabilities through refactors and reformatting","Learn how GitLab's improved Scope+Offset fingerprinting keeps vulnerability tracking stable across comments, blank lines, and reformatting.","https://res.cloudinary.com/about-gitlab-com/image/upload/v1759320418/xjmqcozxzt4frx0hori3.png","2026-08-12",[1161],"Julian Thome","improved-scope-offset-fingerprinting",{"title":1164,"description":1165,"heroImage":1158,"category":425,"date":1166,"authors":1167,"slug":1170,"externalUrl":429},"GitLab Secrets Manager adds ESO, Terraform, API support","Simplify credential management across your stack. GitLab Secrets Manager provides secure retrieval in Kubernetes, Terraform, and external workflows.","2026-08-06",[1168,1169],"Erick Bajao","Joe Randazzo","gitlab-secrets-manager-add-eso-terraform-api-support",{"title":1172,"description":1173,"heroImage":1174,"category":425,"date":1175,"authors":1176,"slug":1178,"externalUrl":429},"Secure every commit to production with Claude and GitLab","Claude Security catches vulnerabilities inside a coding session. GitLab picks up from there, scanning, enforcing policy, and producing audit evidence for the software lifecycle. ","https://res.cloudinary.com/about-gitlab-com/image/upload/v1756122536/akivvcnafog9c4dhhzkp.png","2026-08-03",[1177],"Alisa Ho","claude-security-and-gitlab",{"promotions":1180},[1181,1195,1207,1218],{"id":1182,"categories":1183,"header":1185,"text":1186,"button":1187,"image":1192},"ai-modernization",[1184],"ai","Is AI achieving its promise at scale?","Quiz will take 5 minutes or less",{"text":1188,"config":1189},"Get your AI maturity score",{"href":1190,"dataGaName":1191,"dataGaLocation":658},"/assessments/ai-modernization-assessment/","modernization assessment",{"config":1193},{"src":1194},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/qix0m7kwnd8x2fh1zq49.png",{"id":1196,"categories":1197,"header":1199,"text":1186,"button":1200,"image":1204},"devops-modernization",[1198,993],"product","Are you just managing tools or shipping innovation?",{"text":1201,"config":1202},"Get your DevOps maturity score",{"href":1203,"dataGaName":1191,"dataGaLocation":658},"/assessments/devops-modernization-assessment/",{"config":1205},{"src":1206},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138785/eg818fmakweyuznttgid.png",{"id":1208,"categories":1209,"header":1210,"text":1186,"button":1211,"image":1215},"security-modernization",[425],"Are you trading speed for security?",{"text":1212,"config":1213},"Get your security maturity score",{"href":1214,"dataGaName":1191,"dataGaLocation":658},"/assessments/security-modernization-assessment/",{"config":1216},{"src":1217},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/p4pbqd9nnjejg5ds6mdk.png",{"id":1219,"paths":1220,"header":1223,"text":1224,"button":1225,"image":1230},"github-azure-migration",[1221,1222],"migration-from-azure-devops-to-gitlab","integrating-azure-devops-scm-and-gitlab","Is your team ready for GitHub's Azure move?","GitHub is already rebuilding around Azure. Find out what it means for you.",{"text":1226,"config":1227},"See how GitLab compares to GitHub",{"href":1228,"dataGaName":1229,"dataGaLocation":658},"/compare/gitlab-vs-github/github-azure-migration/","github azure migration",{"config":1231},{"src":1206},{"header":1233,"blurb":1234,"button":1235,"secondaryButton":1240},"Start building faster today","See what your team can do with the intelligent orchestration platform for DevSecOps.\n",{"text":1236,"config":1237},"Get your free trial",{"href":1238,"dataGaName":457,"dataGaLocation":1239},"https://gitlab.com/-/trial_registrations/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/","feature",{"text":931,"config":1241},{"href":783,"dataGaName":462,"dataGaLocation":1239},1786803756474]