[{"data":1,"prerenderedAt":2543},["ShallowReactive",2],{"/ja-jp/blog/migration-guide-github-advanced-security-to-gitlab-ultimate":3,"navigation-ja-jp":1761,"banner-ja-jp":2191,"footer-ja-jp":2199,"blog-post-authors-ja-jp-Fernando Diaz":2440,"blog-related-posts-ja-jp-migration-guide-github-advanced-security-to-gitlab-ultimate":2455,"blog-promotions-ja-jp":2481,"next-steps-ja-jp":2534},{"id":4,"title":5,"authors":6,"body":8,"category":732,"date":1739,"description":1740,"extension":1741,"externalUrl":1742,"faq":1742,"featured":512,"heroImage":1743,"meta":1744,"navigation":512,"path":1745,"seo":1746,"slug":1751,"stem":1752,"tags":1753,"template":1758,"updatedDate":1759,"__hash__":1760},"blogPosts/ja-jp/blog/migration-guide-github-advanced-security-to-gitlab-ultimate.md","GitHub Advanced SecurityプランからGitLab Ultimateプランへの移行ガイド",[7],"Fernando Diaz",{"type":9,"value":10,"toc":1719},"minimark",[11,15,18,34,38,47,52,55,81,85,88,131,139,142,151,177,184,193,207,213,260,279,282,295,309,312,326,329,342,356,394,403,414,417,423,426,432,435,449,456,462,467,470,473,490,603,619,623,626,634,637,648,662,665,674,677,699,707,710,716,719,722,725,740,809,826,829,832,846,853,947,955,958,961,969,972,980,983,986,992,1014,1023,1029,1032,1035,1038,1046,1085,1093,1097,1106,1121,1127,1130,1190,1198,1201,1204,1207,1216,1227,1230,1248,1251,1257,1260,1266,1269,1278,1289,1294,1303,1309,1324,1339,1348,1359,1365,1369,1372,1376,1379,1499,1518,1521,1530,1541,1547,1554,1557,1565,1568,1574,1587,1589,1592,1626,1631,1638,1641,1644,1701,1712,1715],[12,13,14],"p",{},"GitLabは、最も包括的なAIを搭載したDevSecOpsプラットフォームで、ソフトウェアデリバリーライフサイクル全体を1つのプラットフォームで実現することで、より安全で迅速なソフトウェアのリリースを可能にしています。GitHubでは、GitHub内の追加のセキュリティ機能を有効にするAdvanced\nSecurityアドオンを提供してはいますが、GitLabと比較すると、ネイティブに提供するセキュリティ機能の深さと幅広さでは機能の範囲と深さが限定的です。SDLCのすべての領域にわたってセキュリティを強化すべくGitLab\nUltimateプランへの移行を検討している組織は、このガイドを参考にして両製品を比較し、またGitLabプラットフォームに移行するためのチュートリアルとしてもお役立てください。",[12,16,17],{},"この記事には次の内容が含まれます",[19,20,21,25,28,31],"ul",{},[22,23,24],"li",{},"GitLab UltimateとGitHub Advanced Securityの比較",[22,26,27],{},"GitHubリポジトリをGitLabに移行する方法",[22,29,30],{},"GitHub Advanced SecurityからGitLab Ultimateへの機能別の移行方法",[22,32,33],{},"GitLab Ultimateのセキュリティ追加機能の紹介",[35,36,24],"h2",{"id":37},"gitlab-ultimateとgithub-advanced-securityの比較",[12,39,40,46],{},[41,42,45],"a",{"href":43,"rel":44},"https://about.gitlab.com/ja-jp/pricing/ultimate/",[],"GitLab\nUltimate","は、安全なソフトウェアをより速く提供したいと考えている企業向けの、GitLabの最上位サブスクリプションプランです。GitHub\nAdvanced Securityは、追加のセキュリティ機能を有効にするGitHub Enterpriseのアドオンです。",[48,49,51],"h3",{"id":50},"gitlab-ultimateとgithub-advanced-securityの類似点","GitLab UltimateとGitHub Advanced Securityの類似点",[12,53,54],{},"GitLab UltimateとGitHub Advanced Securityの両プランに次の機能が搭載されています。",[19,56,57,66,69,78],{},[22,58,59,60,65],{},"静的アプリケーションセキュリティテスト（",[41,61,64],{"href":62,"rel":63},"https://docs.gitlab.com/ja-jp/user/application_security/sast/",[],"SAST","）、シークレットスキャン、依存関係スキャン",[22,67,68],{},"コンテキスト脆弱性インテリジェンスと解決策のアドバイス",[22,70,71,72,77],{},"依存関係またはソフトウェア部品表のリスト（",[41,73,76],{"href":74,"rel":75},"https://about.gitlab.com/blog/the-ultimate-guide-to-sboms/",[],"SBOM","）",[22,79,80],{},"セキュリティ指標と分析情報",[48,82,84],{"id":83},"gitlab-ultimateとgithub-advanced-securityの相違点","GitLab UltimateとGitHub Advanced Securityの相違点",[12,86,87],{},"GitLab Ultimateは、次の点でGitHub Advanced Securityと異なります。",[19,89,90,105,114,123],{},[22,91,92,93,98,99,104],{},"GitLabは、コンテナスキャン、動的アプリケーションセキュリティテスト（",[41,94,97],{"href":95,"rel":96},"https://docs.gitlab.com/ja-jp/user/application_security/dast/",[],"DAST","）、Web\nAPIファジングなどの追加のコードスキャナーをネイティブに提供します。スキャナーは、カスタムルールセットを備え最適化された、独自のオープンソーステクノロジーを組み合わせたものです。完全なリストについては、",[41,100,103],{"href":101,"rel":102},"https://docs.gitlab.com/ja-jp/user/application_security/secure_your_application/",[],"GitLab\nAppSecのドキュメント","をご覧ください。",[22,106,107,108,113],{},"GitLabは、セキュリティ上問題のあるコードが承認なしにマージされることを防ぐため、",[41,109,112],{"href":110,"rel":111},"https://docs.gitlab.com/ja-jp/user/application_security/policies/",[],"詳細な制御機能（セキュリティガードレール）","を提供しています。",[22,115,116,117,122],{},"GitLabセキュリティスキャナーは、",[41,118,121],{"href":119,"rel":120},"https://docs.gitlab.com/ja-jp/user/application_security/offline_deployments/",[],"インターネット未接続（エアギャップ）環境や制限付きネットワーク環境","でも実行可能です。",[22,124,125,126,113],{},"GitLabは、組織全体のコンプライアンス違反を監視できる",[41,127,130],{"href":128,"rel":129},"https://docs.gitlab.com/ja-jp/user/compliance/compliance_center/",[],"コンプライアンスセンター",[12,132,133,134,138],{},"さらにGitLab\nUltimateでは、追加のセキュリティやコンプライアンス機能、ポートフォリオとバリューストリームの管理、アップグレード時のライブサポート機能なども提供しています。追加機能の詳細については、",[41,135,137],{"href":43,"rel":136},[],"GitLab\nUltimateのドキュメント","を参照してください。",[35,140,27],{"id":141},"githubリポジトリをgitlabに移行する方法",[12,143,144,145,150],{},"GitLabには、GitHub.comまたはGitHub\nEnterpriseからGitHubプロジェクトをGitLabにインポートできるインポーターが組み込まれています。インポーターを使用すると、GitHubリポジトリだけでなく、イシュー、コラボレーター（メンバー）、プルリクエストなど他のオブジェクトもGitLabに移行できます。移行できるものの全リストについては、",[41,146,149],{"href":147,"rel":148},"https://docs.gitlab.com/ja-jp/user/project/import/github/#imported-data",[],"GitHubインポートされたデータのドキュメント","を参照してください。移行は次の手順で行います。",[152,153,154,162,172],"ol",{},[22,155,156,157,161],{},"左側のサイドバー上部で ",[158,159,160],"strong",{},"新規作成（+）"," を選択する",[22,163,164,167,168,171],{},[158,165,166],{},"GitLab内","セクションで",[158,169,170],{},"新しいプロジェクト/リポジトリ","を選択する",[22,173,174,171],{},[158,175,176],{},"プロジェクトのインポート",[12,178,179],{},[180,181],"img",{"alt":182,"src":183},"迷路化したバージョンの中心にGitLabのアイコン","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/1-Import-Project.png",[152,185,187],{"start":186},4,[22,188,189,192],{},[158,190,191],{},"GitHub","ボタンを押す",[19,194,195,204],{},[22,196,197,198,203],{},"GitLab\nSelf-Managedを使用している場合は、",[41,199,202],{"href":200,"rel":201},"https://docs.gitlab.com/ja-jp/administration/settings/import_and_export_settings/#configure-allowed-import-sources",[],"GitHubインポーターを有効にする","必要があります",[22,205,206],{},"他のインポーターも同様の方法で開始できます",[152,208,210],{"start":209},5,[22,211,212],{},"これで、以下のいずれかが可能になりました",[19,214,215,221],{},[22,216,217,220],{},[158,218,219],{},"GitHubで認証","を選択して、GitHub Oauthで認証する",[22,222,223,224],{},"GitHubのパーソナルアクセストークンを使う",[19,225,226,233,239,245,251,257],{},[22,227,228,232],{},[41,229,230],{"href":230,"rel":231},"https://github.com/settings/tokens/new",[],"に移動します",[22,234,235,238],{},[158,236,237],{},"Note","フィールドにトークンの説明を入力します",[22,240,241,244],{},[158,242,243],{},"リポジトリ","スコープを選択します",[22,246,247,248,244],{},"オプションとしてコラボレーターをインポートするには、",[158,249,250],{},"read:org",[22,252,253,256],{},[158,254,255],{},"トークンを生成","ボタンを押します",[22,258,259],{},"GitLabのインポートページのパーソナルアクセストークンフィールドに、GitHubのパーソナルアクセストークンを貼り付けます",[152,261,263,268,271,274],{"start":262},6,[22,264,265,192],{},[158,266,267],{},"認証",[22,269,270],{},"移行するアイテムを選択する",[22,272,273],{},"移行するプロジェクトと場所を選択する",[22,275,276,192],{},[158,277,278],{},"インポート",[12,280,281],{},"インポートされたプロジェクトがワークスペースにあることをご確認ください。GitHubからGitLabへの移行に関するさらに詳しいガイダンスは、次の動画をご覧ください。",[283,284,287,288],"figure",{"className":285},[286],"video_container","\n  ",[289,290,294],"iframe",{"src":291,"frameBorder":292,"allowFullScreen":293},"https://www.youtube.com/embed/0Id5oMl1Kqs?si=HEpZVy94cpfPfAky","0","true"," ",[12,296,297,298,303,304],{},"REST\nAPI](",[41,299,302],{"href":300,"rel":301},"https://docs.gitlab.com/ja-jp/user/project/import/github/#use-the-api)%E3%82%92%E4%BD%BF%E7%94%A8%E3%81%97%E3%81%9F%E7%A7%BB%E8%A1%8C%E3%82%82%E5%8F%AF%E8%83%BD%E3%81%A7%E3%81%99%E3%80%82%E3%81%BE%E3%81%9F%E3%80%81%E3%82%A4%E3%83%B3%E3%83%9D%E3%83%BC%E3%82%BF%E3%83%BC%E3%81%AF%E3%80%81Bitbucket%E3%82%84Gitea%E3%81%AA%E3%81%A9%E3%81%AE%E4%BB%96%E3%81%AE%E3%82%BD%E3%83%BC%E3%82%B9%E3%81%8B%E3%82%89%E3%81%AE%E3%82%A4%E3%83%B3%E3%83%9D%E3%83%BC%E3%83%88%E3%82%82%E6%94%AF%E6%8F%B4%E3%81%97%E3%81%BE%E3%81%99%E3%80%82%E8%A9%B3%E7%B4%B0%E3%81%AB%E3%81%A4%E3%81%84%E3%81%A6%E3%81%AF%E3%80%81%5B%E3%82%A4%E3%83%B3%E3%83%9D%E3%83%BC%E3%82%BF%E3%83%BC%E3%81%AE%E3%83%89%E3%82%AD%E3%83%A5%E3%83%A1%E3%83%B3%E3%83%88",[],"https://docs.gitlab.com/ja-jp/user/project/import/github/#use-the-api)を使用した移行も可能です。また、インポーターは、BitbucketやGiteaなどの他のソースからのインポートも支援します。詳細については、[インポーターのドキュメント","](",[41,305,308],{"href":306,"rel":307},"https://docs.gitlab.com/ja-jp/user/import/)%E3%82%92%E5%8F%82%E7%85%A7%E3%81%97%E3%81%A6%E3%81%8F%E3%81%A0%E3%81%95%E3%81%84%E3%80%82",[],"https://docs.gitlab.com/ja-jp/user/import/)を参照してください。",[35,310,311],{"id":311},"機能別の移行方法",[12,313,314,315,319,320,325],{},"次は、GitLab UltimateのGitHub Advanced\nSecurityが提供する各機能の活用方法について見てみましょう。続行するには、",[41,316,318],{"href":43,"rel":317},[],"GitLab\nUltimateライセンス","が必要です。GitLabは、",[41,321,324],{"href":322,"rel":323},"https://about.gitlab.com/ja-jp/free-trial/devsecops/",[],"無料トライアル","がお試しいただけます。",[48,327,328],{"id":328},"コードスキャン",[12,330,331,332,335,336,341],{},"GitHubでは、静的ソースコードの文脈上の脆弱性インテリジェンスやアドバイスを提供する目的でコードスキャンを実行しています。",[41,333,64],{"href":62,"rel":334},[],"を有効にすることで、GitLab内でも同じことができます。GitLab\nSASTスキャナーは、GitHubの",[41,337,340],{"href":338,"rel":339},"https://docs.github.com/en/code-security/code-scanning/introduction-to-code-scanning/about-code-scanning-with-codeql#about-codeql",[],"CodeQL","よりも幅広いプログラミング言語とフレームワークをカバーしています。",[12,343,344,345,350,351,355],{},"GitLabでコードスキャンを有効にすれば、",[41,346,349],{"href":347,"rel":348},"https://docs.gitlab.com/ja-jp/user/application_security/sast/#configure-sast-in-your-cicd-yaml",[],"SASTテンプレート","を",[352,353,354],"code",{},".gitlab-ci.yml","に追加するだけです。",[357,358,363],"pre",{"className":359,"code":360,"language":361,"meta":362,"style":362},"language-yaml shiki shiki-themes github-light","include:\n  - template: Jobs/SAST.gitlab-ci.yml\n","yaml","",[352,364,365,378],{"__ignoreMap":362},[366,367,370,374],"span",{"class":368,"line":369},"line",1,[366,371,373],{"class":372},"shJU0","include",[366,375,377],{"class":376},"sgsFI",":\n",[366,379,381,384,387,390],{"class":368,"line":380},2,[366,382,383],{"class":376},"  - ",[366,385,386],{"class":372},"template",[366,388,389],{"class":376},": ",[366,391,393],{"class":392},"sYBdl","Jobs/SAST.gitlab-ci.yml\n",[12,395,396,397,402],{},"テンプレートが追加されると、新しいコードがチェックインされるたびに、SASTはプロジェクトで使用されている",[41,398,401],{"href":399,"rel":400},"https://docs.gitlab.com/ja-jp/user/application_security/sast/#supported-languages-and-frameworks",[],"プログラミング言語","を自動的に検出します。そして、ソースコードに既知の脆弱性がないかスキャンします。",[12,404,405,408,409,138],{},[158,406,407],{},"注：","\nセキュリティスキャナーは、GitLabのセキュリティ設定からプロジェクトに追加することもできます。これにより、パイプラインを更新するためのマージリクエストを自動的に作成できます。詳細については、",[41,410,413],{"href":411,"rel":412},"https://docs.gitlab.com/ja-jp/user/application_security/sast/#configure-sast-by-using-the-ui",[],"UIドキュメントを使用してSASTを構成する",[12,415,416],{},"フィーチャーブランチとターゲットブランチの差分のSAST結果は、マージリクエストウィジェットで表示されます。マージリクエストウィジェットには、マージリクエストで行われた変更によって導入されたSASTの結果と解決策が表示されます。",[12,418,419],{},[180,420],{"alt":421,"src":422},"マージリクエストでのセキュリティスキャン","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/2-SAST-MR-View.png",[12,424,425],{},"どの脆弱性にも、詳細な説明、重大度、場所、解決情報など、修正を支援するデータが表示されます。",[12,427,428],{},[180,429],{"alt":430,"src":431},"SASTの脆弱性の詳細","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/3-SAST-MR-View-Detailed.png",[12,433,434],{},"脆弱性への対処として次が挙げられます。",[19,436,437,443],{},[22,438,439,442],{},[158,440,441],{},"脆弱性を無視","：デベロッパーがコメントで脆弱性を無視できるようにします。そうすることで、セキュリティチームがレビューを実行できるようになります。",[22,444,445,448],{},[158,446,447],{},"イシューを作成","：イシューを作成して、追加の監視が必要な脆弱性を追跡できるようにします。",[12,450,451,452,455],{},"これらの変更内容は、マージリクエスト内の",[158,453,454],{},"差分表示画面","でもインラインで確認できます。",[12,457,458],{},[180,459],{"alt":460,"src":461},"SASTの脆弱性がビューを変更","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/4-SAST-MR-View-Changes.png",[463,464,466],"h4",{"id":465},"sastスキャナーのカスタマイズ","SASTスキャナーのカスタマイズ",[12,468,469],{},"GitLabでは、SASTジョブの定義を上書きできるため、変数、依存関係、ルールなどのプロパティを変更できます。これは、SASTジョブと同じ名前のジョブ名を宣言し、上書きして実行できます。次に、テンプレートをインクルードした後にこの新しいジョブを配置し、その下に追加のキーを指定します。",[12,471,472],{},"たとえば、次のような設定ができます：",[19,474,475,481,487],{},[22,476,477,480],{},[352,478,479],{},"semgrep-sast","スキャナーが使用するバージョンを上書きする",[22,482,483,486],{},[352,484,485],{},"gosec-sast","を実行する前に、プライベートプロジェクトからモジュールを取得するスクリプトを実行する",[22,488,489],{},"すべてのスキャナーが最大深度10で検索するように設定する",[357,491,493],{"className":359,"code":492,"language":361,"meta":362,"style":362},"include：\n  - template：Jobs/SAST.gitlab-ci.yml\n\nvariables：\n  SEARCH_MAX_DEPTH：10\n\nsemgrep-sast：\n  variables：\n    SAST_ANALYZER_IMAGE_TAG：\"3.7\"\n\ngosec-sast：\n  before_script：\n    - |\n      cat \u003C\u003CEOF > ~/.netrc\n      machine gitlab.com\n      login $CI_DEPLOY_USER\n      password $CI_DEPLOY_PASSWORD\n      EOF\n",[352,494,495,500,507,514,519,524,528,534,540,546,551,557,563,573,579,585,591,597],{"__ignoreMap":362},[366,496,497],{"class":368,"line":369},[366,498,499],{"class":392},"include：\n",[366,501,502,504],{"class":368,"line":380},[366,503,383],{"class":376},[366,505,506],{"class":392},"template：Jobs/SAST.gitlab-ci.yml\n",[366,508,510],{"class":368,"line":509},3,[366,511,513],{"emptyLinePlaceholder":512},true,"\n",[366,515,516],{"class":368,"line":186},[366,517,518],{"class":392},"variables：\n",[366,520,521],{"class":368,"line":209},[366,522,523],{"class":392},"  SEARCH_MAX_DEPTH：10\n",[366,525,526],{"class":368,"line":262},[366,527,513],{"emptyLinePlaceholder":512},[366,529,531],{"class":368,"line":530},7,[366,532,533],{"class":392},"semgrep-sast：\n",[366,535,537],{"class":368,"line":536},8,[366,538,539],{"class":392},"  variables：\n",[366,541,543],{"class":368,"line":542},9,[366,544,545],{"class":392},"    SAST_ANALYZER_IMAGE_TAG：\"3.7\"\n",[366,547,549],{"class":368,"line":548},10,[366,550,513],{"emptyLinePlaceholder":512},[366,552,554],{"class":368,"line":553},11,[366,555,556],{"class":392},"gosec-sast：\n",[366,558,560],{"class":368,"line":559},12,[366,561,562],{"class":392},"  before_script：\n",[366,564,566,569],{"class":368,"line":565},13,[366,567,568],{"class":376},"    - ",[366,570,572],{"class":571},"sD7c4","|\n",[366,574,576],{"class":368,"line":575},14,[366,577,578],{"class":392},"      cat \u003C\u003CEOF > ~/.netrc\n",[366,580,582],{"class":368,"line":581},15,[366,583,584],{"class":392},"      machine gitlab.com\n",[366,586,588],{"class":368,"line":587},16,[366,589,590],{"class":392},"      login $CI_DEPLOY_USER\n",[366,592,594],{"class":368,"line":593},17,[366,595,596],{"class":392},"      password $CI_DEPLOY_PASSWORD\n",[366,598,600],{"class":368,"line":599},18,[366,601,602],{"class":392},"      EOF\n",[12,604,605,607,608,613,614,138],{},[158,606,407],{}," 利用可能なSASTジョブは、",[41,609,612],{"href":610,"rel":611},"https://gitlab.com/gitlab-org/gitlab/-/blob/master/lib/gitlab/ci/templates/Jobs/SAST.gitlab-ci.yml",[],"' SAST.gitlab-ci.yml `テンプレート","にあります。設定については、",[41,615,618],{"href":616,"rel":617},"https://docs.gitlab.com/ja-jp/user/application_security/sast/#available-cicd-variables",[],"利用可能なSAST\nCI/CD変数のドキュメント",[463,620,622],{"id":621},"sastルールセットのカスタマイズ","SASTルールセットのカスタマイズ",[12,624,625],{},"GitLabはSASTアナライザーごとにコードを処理し、ルールを使用してソースコードの脆弱性を特定します。これらのルールは、スキャナーが報告する弱点の種類を決定します。",[19,627,628,631],{},[22,629,630],{},"Semgrepを基盤としたSASTスキャナーについては、GitLabが検出ルールの作成、保守、サポートを一括して提供しています。Semgrepオープンソースエンジン、GitLabの管理による検出ルール、脆弱性追跡と誤検出のためのGitLab独自の技術を集結しています。",[22,632,633],{},"他のSASTアナライザーの場合、ルールは各スキャナーのupstreamプロジェクトで定義されています。",[12,635,636],{},"スキャンされるリポジトリ内の設定ファイルを定義することで、SASTスキャナーの動作をカスタマイズできます。",[19,638,639,642,645],{},[22,640,641],{},"事前定義されたルールを無効にする（すべてのアナライザーで利用可能）",[22,643,644],{},"事前定義されたルールを上書きする（すべてのアナライザーで利用可能）",[22,646,647],{},"パススルーを使用してカスタム設定を合成することにより、事前定義されたルールを置き換える",[12,649,650,651,656,657,138],{},"SASTルールの設定の詳細と例については、",[41,652,655],{"href":653,"rel":654},"https://docs.gitlab.com/ja-jp/user/application_security/sast/rules/",[],"SASTルール","と",[41,658,661],{"href":659,"rel":660},"https://docs.gitlab.com/ja-jp/user/application_security/sast/customize_rulesets/",[],"ルールセットのカスタマイズのドキュメント",[48,663,664],{"id":664},"シークレットスキャン",[12,666,667,668,673],{},"GitHubは、流出したシークレットを見つけ、ブロックし、取り消すことができるシークレットスキャンをサポートします。",[41,669,672],{"href":670,"rel":671},"https://docs.gitlab.com/ja-jp/user/application_security/secret_detection/",[],"シークレット検出","を有効にすることで、GitLab内でも同じことができます。",[12,675,676],{},"GitLabでシークレット検出を有効にするには、次のテンプレートを'.gitlab-ci.yml `に追加するだけです。",[357,678,680],{"className":359,"code":679,"language":361,"meta":362,"style":362},"include:\n  - template: Jobs/Secret-Detection.gitlab-ci.yml\n",[352,681,682,688],{"__ignoreMap":362},[366,683,684,686],{"class":368,"line":369},[366,685,373],{"class":372},[366,687,377],{"class":376},[366,689,690,692,694,696],{"class":368,"line":380},[366,691,383],{"class":376},[366,693,386],{"class":372},[366,695,389],{"class":376},[366,697,698],{"class":392},"Jobs/Secret-Detection.gitlab-ci.yml\n",[12,700,701,702,138],{},"テンプレートが追加されると、新しいコードがチェックインされる（またはパイプラインが実行される）たびに、シークレットスキャナーは既知のシークレットのソースコードをスキャンします。パイプラインでのシークレット検出は、コードの各要素を別々にスキャンします。「デフォルトブランチ」を除くすべてのメソッドでは、パイプラインシークレット検出はワークツリーではなくコミットをスキャンします。シークレットスキャンの仕組みについては、",[41,703,706],{"href":704,"rel":705},"https://docs.gitlab.com/ja-jp/user/application_security/secret_detection/pipeline/#coverage",[],"シークレット検出カバレッジドキュメント",[12,708,709],{},"マージリクエストを作成する際、シークレット検出はソースブランチで行われたすべてのコミットをスキャンします。SASTと同様に、検出されたすべての脆弱性から、修正プロセスを支援するため、以下の情報（ロケーションなど）や識別子を提供します。",[12,711,712],{},[180,713],{"alt":714,"src":715},"シークレット検出の脆弱性の詳細","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/5-Secret-Detection-MR-Detailed.png",[12,717,718],{},"SASTと同様に、マージリクエストから直接、脆弱性の無視やイシューの作成など、検出された脆弱性に対するアクションを取ることができます。",[463,720,721],{"id":721},"シークレット検出ジョブのカスタマイズ",[12,723,724],{},"GitLabではシークレット検出ジョブの定義を上書きして、変数や依存関係、ルールなどのプロパティを変更できます。上書きするには、シークレット検出ジョブと同名のジョブを宣言します。次に、テンプレートをインクルードした後に新しいジョブを配置し、その下に追加のキーを指定します。たとえば、次のような設定です。",[19,726,727,734,737],{},[22,728,729,730,733],{},"シークレット検出ジョブの実行ステージを",[352,731,732],{},"security","に上書きする",[22,735,736],{},"過去のコミットに対するスキャンを有効にする",[22,738,739],{},"シークレットアナライザーのバージョンを4.5に変更する",[357,741,743],{"className":359,"code":742,"language":361,"meta":362,"style":362},"include:\n  - template: Jobs/Secret-Detection.gitlab-ci.yml\n\nsecret_detection:\n  stage: security\n  variables:\n    SECRET_DETECTION_HISTORIC_SCAN: \"true\"\n    SECRETS_ANALYZER_VERSION: \"4.5\"\n",[352,744,745,751,761,765,772,782,789,799],{"__ignoreMap":362},[366,746,747,749],{"class":368,"line":369},[366,748,373],{"class":372},[366,750,377],{"class":376},[366,752,753,755,757,759],{"class":368,"line":380},[366,754,383],{"class":376},[366,756,386],{"class":372},[366,758,389],{"class":376},[366,760,698],{"class":392},[366,762,763],{"class":368,"line":509},[366,764,513],{"emptyLinePlaceholder":512},[366,766,767,770],{"class":368,"line":186},[366,768,769],{"class":372},"secret_detection",[366,771,377],{"class":376},[366,773,774,777,779],{"class":368,"line":209},[366,775,776],{"class":372},"  stage",[366,778,389],{"class":376},[366,780,781],{"class":392},"security\n",[366,783,784,787],{"class":368,"line":262},[366,785,786],{"class":372},"  variables",[366,788,377],{"class":376},[366,790,791,794,796],{"class":368,"line":530},[366,792,793],{"class":372},"    SECRET_DETECTION_HISTORIC_SCAN",[366,795,389],{"class":376},[366,797,798],{"class":392},"\"true\"\n",[366,800,801,804,806],{"class":368,"line":536},[366,802,803],{"class":372},"    SECRETS_ANALYZER_VERSION",[366,805,389],{"class":376},[366,807,808],{"class":392},"\"4.5\"\n",[12,810,811,813,814,819,820,825],{},[158,812,407],{},"\n利用可能なシークレット検出ジョブは、",[41,815,818],{"href":816,"rel":817},"https://gitlab.com/gitlab-org/gitlab/-/blob/master/lib/gitlab/ci/templates/Jobs/Secret-Detection.gitlab-ci.yml",[],"SAST.gitlab-ci.ymlテンプレート","にあります。利用可能な設定は、",[41,821,824],{"href":822,"rel":823},"https://docs.gitlab.com/ja-jp/user/application_security/secret_detection/pipeline/#customizing-analyzer-settings",[],"利用可能なシークレット検出CI/CD変数のドキュメント","に記載されています。",[463,827,828],{"id":828},"シークレット検出ルールセットのカスタマイズ",[12,830,831],{},"シークレット検出アナライザーでは、GitLab\nUIに表示されるシークレットをカスタマイズできます。次のカスタマイズオプションは、個別または組み合わせて使用できます。",[19,833,834,837,840,843],{},[22,835,836],{},"定義済みルールを無効にする",[22,838,839],{},"定義済みルールを上書きする",[22,841,842],{},"カスタム設定を合成する",[22,844,845],{},"リモート設定ファイルを指定する",[12,847,848,849,852],{},"たとえば、",[352,850,851],{},".gitlab/secret-detection-ruleset.toml","というファイルをプロジェクトのルートディレクトリに作成すると、デフォルトのGitLeaksパッケージがテストトークンの検出を無視するように拡張されます。",[357,854,856],{"className":359,"code":855,"language":361,"meta":362,"style":362},"### extended-gitleaks-config.toml\ntitle = \"extension of gitlab's default gitleaks config\"\n\n[extend]\n### Extends default packaged path\npath = \"/gitleaks.toml\"\n\n[allowlist]\n  description = \"allow list of test tokens to ignore in detection\"\n  regexTarget = \"match\"\n  regexes = [\n    '''glpat-1234567890abcdefghij''',\n  ]\n",[352,857,858,864,869,873,884,889,894,898,907,912,917,922,942],{"__ignoreMap":362},[366,859,860],{"class":368,"line":369},[366,861,863],{"class":862},"sAwPA","### extended-gitleaks-config.toml\n",[366,865,866],{"class":368,"line":380},[366,867,868],{"class":392},"title = \"extension of gitlab's default gitleaks config\"\n",[366,870,871],{"class":368,"line":509},[366,872,513],{"emptyLinePlaceholder":512},[366,874,875,878,881],{"class":368,"line":186},[366,876,877],{"class":376},"[",[366,879,880],{"class":392},"extend",[366,882,883],{"class":376},"]\n",[366,885,886],{"class":368,"line":209},[366,887,888],{"class":862},"### Extends default packaged path\n",[366,890,891],{"class":368,"line":262},[366,892,893],{"class":392},"path = \"/gitleaks.toml\"\n",[366,895,896],{"class":368,"line":530},[366,897,513],{"emptyLinePlaceholder":512},[366,899,900,902,905],{"class":368,"line":536},[366,901,877],{"class":376},[366,903,904],{"class":392},"allowlist",[366,906,883],{"class":376},[366,908,909],{"class":368,"line":542},[366,910,911],{"class":392},"  description = \"allow list of test tokens to ignore in detection\"\n",[366,913,914],{"class":368,"line":548},[366,915,916],{"class":392},"  regexTarget = \"match\"\n",[366,918,919],{"class":368,"line":553},[366,920,921],{"class":392},"  regexes = [\n",[366,923,924,927,931,934,936,939],{"class":368,"line":559},[366,925,926],{"class":392},"    '",[366,928,930],{"class":929},"sYu0t","''",[366,932,933],{"class":392},"glpat-1234567890abcdefghij",[366,935,930],{"class":929},[366,937,938],{"class":392},"'",[366,940,941],{"class":376},",\n",[366,943,944],{"class":368,"line":565},[366,945,946],{"class":376},"  ]\n",[12,948,949,950,138],{},"定義済みのアナライザールールを上書きする方法については、",[41,951,954],{"href":952,"rel":953},"https://docs.gitlab.com/ja-jp/user/application_security/secret_detection/pipeline/#override-predefined-analyzer-rules",[],"シークレット検出のドキュメント",[463,956,957],{"id":957},"シークレット漏洩時の自動対応機能",[12,959,960],{},"GitLabシークレット検出は、特定のタイプの流出したシークレットを発見すると自動的に対応します。自動対応には次のようなアクションがあります。",[19,962,963,966],{},[22,964,965],{},"自動的にシークレットを失効させる",[22,967,968],{},"シークレットを発行したパートナーに通知し、パートナーはシークレットを取り消すか、その所有者に通知するか、またはその他の方法で不正利用からの保護につなげる",[12,970,971],{},"GitLabは、パートナーが発行した認証情報がGitLab.comの公開リポジトリに流出した場合、パートナーへの通知も可能です。クラウドやSaaS製品を運用していて、このような通知の受け取りに興味があるという場合、GitLab\nToken Revocation APIから呼び出されるPartner APIを実装できます。",[12,973,974,975,138],{},"詳しくは",[41,976,979],{"href":977,"rel":978},"https://docs.gitlab.com/ja-jp/user/application_security/secret_detection/automatic_response/",[],"流出したシークレットへの自動対応",[48,981,982],{"id":982},"サプライチェーンのセキュリティ",[12,984,985],{},"GitHubは、自動化されたセキュリティとバージョン更新、ワンクリックのSBOMにより、ソフトウェアサプライチェーンのセキュリティ確保、管理、レポートを可能にします。GitLabは依存関係スキャンと依存関係リスト（SBOM）機能を使って、サプライチェーンセキュリティのニーズを満たすことができます。",[12,987,988,989,991],{},"GitLabで依存関係スキャンを有効にするには、",[352,990,354],{},"に以下のテンプレートを追加するだけです：",[357,993,995],{"className":359,"code":994,"language":361,"meta":362,"style":362},"include:\n  - template: Jobs/Dependency-Scanning.gitlab-ci.yml\n",[352,996,997,1003],{"__ignoreMap":362},[366,998,999,1001],{"class":368,"line":369},[366,1000,373],{"class":372},[366,1002,377],{"class":376},[366,1004,1005,1007,1009,1011],{"class":368,"line":380},[366,1006,383],{"class":376},[366,1008,386],{"class":372},[366,1010,389],{"class":376},[366,1012,1013],{"class":392},"Jobs/Dependency-Scanning.gitlab-ci.yml\n",[12,1015,1016,1017,1022],{},"テンプレートが追加されると、新しいコードがチェックインされるたびに、依存関係スキャンがプロジェクトで使われている",[41,1018,1021],{"href":1019,"rel":1020},"https://docs.gitlab.com/ja-jp/user/application_security/dependency_scanning/#supported-languages-and-package-managers",[],"パッケージマネージャ","を自動検出します。そして、使用されている依存関係に既知の脆弱性がないかスキャンします。フィーチャーブランチとターゲットブランチの差分の依存関係のスキャン結果は、マージリクエストウィジェットに表示されます。マージリクエストウィジェットは、マージリクエストで行われた変更によって導入された依存関係スキャンの結果と解決策を表示します。マージリクエストの中で、検出された脆弱性は、識別子、証拠、解決策といった、修正を支援する関連情報を表示します。",[12,1024,1025],{},[180,1026],{"alt":1027,"src":1028},"依存関係スキャナーの脆弱性の詳細","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/6-Dependency-Scanner-MR-View-Detailed.png",[12,1030,1031],{},"SASTやシークレット検出と同様に、脆弱性の無視やイシューの作成など、これらの脆弱性に対するアクションをマージリクエストから直接実行できます。",[463,1033,1034],{"id":1034},"依存関係スキャンの設定",[12,1036,1037],{},"ジョブの定義を上書きするには（たとえば、変数や依存関係のようなプロパティを変更するには）、上書き対象のジョブと同じ名前で新しいジョブを宣言します。テンプレートをインクルードした後に新しいジョブを配置し、その下に追加のキーを指定します。たとえば、次のコードでは以下の設定を行っています。",[19,1039,1040,1043],{},[22,1041,1042],{},"脆弱な依存関係の自動修正を無効にする",[22,1044,1045],{},"依存関係スキャンの実行前にビルドジョブの完了を要求する",[357,1047,1049],{"className":359,"code":1048,"language":361,"meta":362,"style":362},"include：\n  - template：Jobs/Dependency-Scanning.gitlab-ci.yml\n\ngemnasium-dependency_scanning：\n  variables：\n    DS_REMEDIATE：\"false\"\n  dependencies：[\"build\"]\n",[352,1050,1051,1055,1062,1066,1071,1075,1080],{"__ignoreMap":362},[366,1052,1053],{"class":368,"line":369},[366,1054,499],{"class":392},[366,1056,1057,1059],{"class":368,"line":380},[366,1058,383],{"class":376},[366,1060,1061],{"class":392},"template：Jobs/Dependency-Scanning.gitlab-ci.yml\n",[366,1063,1064],{"class":368,"line":509},[366,1065,513],{"emptyLinePlaceholder":512},[366,1067,1068],{"class":368,"line":186},[366,1069,1070],{"class":392},"gemnasium-dependency_scanning：\n",[366,1072,1073],{"class":368,"line":209},[366,1074,539],{"class":392},[366,1076,1077],{"class":368,"line":262},[366,1078,1079],{"class":392},"    DS_REMEDIATE：\"false\"\n",[366,1081,1082],{"class":368,"line":530},[366,1083,1084],{"class":392},"  dependencies：[\"build\"]\n",[12,1086,1087,1088,138],{},"依存関係スキャナーの設定についての詳細は、",[41,1089,1092],{"href":1090,"rel":1091},"https://docs.gitlab.com/ja-jp/user/application_security/dependency_scanning/#customizing-analyzer-behavior",[],"アナライザーの動作をカスタマイズするドキュメント",[463,1094,1096],{"id":1095},"sbomの生成","SBOMの生成",[12,1098,1099,1100,1105],{},"GitLabの依存関係リスト（SBOM）で、プロジェクトやグループの依存関係や、既知の脆弱性を含む依存関係の重要な詳細を確認できます。このリストには、プロジェクトにおける依存関係が集約されており、既知のものや新たに検出されたものの両方が含まれています。依存関係リストは、依存関係スキャナーが",[41,1101,1104],{"href":1102,"rel":1103},"https://docs.gitlab.com/ja-jp/user/project/repository/branches/default/",[],"デフォルトブランチ","で正常に実行された後に生成されます。依存関係リストにアクセスするには",[152,1107,1108,1115],{},[22,1109,1110,1111,1114],{},"左サイドバーで、",[158,1112,1113],{},"検索または移動先..."," を選択し、プロジェクトを見つけます。",[22,1116,1117,1120],{},[158,1118,1119],{},"セキュリティ > 依存関係リスト","の順に選択します。",[12,1122,1123],{},[180,1124],{"alt":1125,"src":1126},"依存関係リスト（SBOM）","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/7-Dependency-List.png",[12,1128,1129],{},"ここから、依存関係に関する次の情報を表示できます。",[1131,1132,1133,1146],"table",{},[1134,1135,1136],"thead",{},[1137,1138,1139,1143],"tr",{},[1140,1141,1142],"th",{},"フィールド",[1140,1144,1145],{},"説明",[1147,1148,1149,1158,1166,1174,1182],"tbody",{},[1137,1150,1151,1155],{},[1152,1153,1154],"td",{},"コンポーネント",[1152,1156,1157],{},"依存関係の名前とバージョン。",[1137,1159,1160,1163],{},[1152,1161,1162],{},"パッケージャー",[1152,1164,1165],{},"依存関係のインストールに使用されるパッケージャー。",[1137,1167,1168,1171],{},[1152,1169,1170],{},"ロケーション",[1152,1172,1173],{},"システムの依存関係の場合、スキャンされたイメージのリストが表示されます。アプリケーションの依存関係の場合、依存関係を宣言したプロジェクト内のパッケージャー固有のロックファイルへのリンクが表示されます。また、トップレベルの依存関係への依存関係パスも表示されます（該当の依存関係が存在する場合）。",[1137,1175,1176,1179],{},[1152,1177,1178],{},"ライセンス",[1152,1180,1181],{},"依存関係のソフトウェアライセンスへのリンク依存関係で検出された脆弱性の数を示す警告バッジ。",[1137,1183,1184,1187],{},[1152,1185,1186],{},"プロジェクト",[1152,1188,1189],{},"依存関係のあるプロジェクトへのリンク。同じ依存関係を持つプロジェクトが複数ある場合、プロジェクトの合計数が表示されます。依存関係のあるプロジェクトに移動するには、プロジェクトの番号を選択し、その名前を検索して選択します。プロジェクト検索機能は、グループ階層内に最大600件のプロジェクトがあるグループでのみサポートされています。",[12,1191,1192,1193,138],{},"詳細については、",[41,1194,1197],{"href":1195,"rel":1196},"https://docs.gitlab.com/ja-jp/user/application_security/dependency_list/",[],"依存関係リストのドキュメント",[48,1199,1200],{"id":1200},"セキュリティとコンプライアンスの管理",[12,1202,1203],{},"GitHub Advanced\nSecurityを使用すると、セキュリティメトリクスとインサイトを閲覧し、コードセキュリティリスクを評価できます。次に、GitLab\nUltimateで同じことをする方法を見てみましょう。",[463,1205,1206],{"id":1206},"セキュリティメトリクスとインサイトの閲覧",[12,1208,1209,1210,1215],{},"GitLabは、アプリケーションのセキュリティ状況を評価するのに役立つ",[41,1211,1214],{"href":1212,"rel":1213},"https://docs.gitlab.com/ja-jp/user/application_security/security_dashboard/",[],"セキュリティダッシュボード","を提供しています。ダッシュボードには、プロジェクトで実行されたセキュリティスキャナーによって検出された脆弱性のメトリクス、評価、チャートがまとめて表示されます。",[19,1217,1218,1221,1224],{},[22,1219,1220],{},"グループ内のすべてのプロジェクトの30日、60日、90日間の期間にわたる脆弱性の傾向",[22,1222,1223],{},"脆弱性の重大度に基づく各プロジェクトの評価（A~Fの文字グレード評価）",[22,1225,1226],{},"過去365日以内に検出された脆弱性の総数とその重大度",[12,1228,1229],{},"セキュリティダッシュボードにアクセスする方法：",[152,1231,1232,1238,1245],{},[22,1233,1234,1235,1237],{},"左側のサイドバーで、",[158,1236,1113],{}," を選択し、プロジェクトまたはグループを見つけます。",[22,1239,1240,1241,1244],{},"サイドタブから、",[158,1242,1243],{},"セキュリティ > セキュリティ"," ダッシュボードを選択します。",[22,1246,1247],{},"必要なものを絞り込んで検索します。",[12,1249,1250],{},"グループビューには、グループ内のすべてのプロジェクトのセキュリティ状況が表示されます。",[12,1252,1253],{},[180,1254],{"alt":1255,"src":1256},"グループセキュリティダッシュボード","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/8-SD-Group.png",[12,1258,1259],{},"プロジェクトビューには、あるプロジェクトのみのセキュリティ体制が表示されます。",[12,1261,1262],{},[180,1263],{"alt":1264,"src":1265},"プロジェクトセキュリティダッシュボード","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/9-SD-Project.png",[463,1267,1268],{"id":1268},"コードのセキュリティリスクを評価",[12,1270,1271,1272,1277],{},"GitLab\nUltimateは、デフォルトブランチのスキャン結果から脆弱性に関する情報を提供する",[41,1273,1276],{"href":1274,"rel":1275},"https://docs.gitlab.com/ja-jp/user/application_security/vulnerability_report/",[],"脆弱性レポート","を備えています。レポートには、パイプラインが成功したかどうかにかかわらず、すべての成功したジョブの累積結果が含まれます。すべてのレベルで、脆弱性レポートには次が表示されます。",[19,1279,1280,1283,1286],{},[22,1281,1282],{},"重大度レベルごとの脆弱性の合計",[22,1284,1285],{},"一般的な脆弱性の属性のフィルター",[22,1287,1288],{},"表形式のレイアウトで表示される各脆弱性の詳細",[12,1290,1291],{},[180,1292],{"alt":1276,"src":1293},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/10-Vulnerability-Report.png",[12,1295,1296,1297,1302],{},"脆弱性をクリックすると、その",[41,1298,1301],{"href":1299,"rel":1300},"https://docs.gitlab.com/ja-jp/user/application_security/vulnerabilities/",[],"脆弱性ページ","にアクセスできます。このページには、脆弱性の説明、ロケーション、識別子などの情報が記載されています。以下は、SASTスキャナーによって検出されたSQLインジェクションの脆弱性のページの例です。",[12,1304,1305],{},[180,1306],{"alt":1307,"src":1308},"SQLインジェクションの脆弱性ページ","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/11-Vulnerability-Page-1.png",[12,1310,1311,1312,1317,1318,1323],{},"ここから、セキュリティチームは、",[41,1313,1316],{"href":1314,"rel":1315},"https://docs.gitlab.com/ja-jp/user/application_security/vulnerabilities/#change-the-status-of-a-vulnerability",[],"理由とともに脆弱性の状態を変更","し、",[41,1319,1322],{"href":1320,"rel":1321},"https://docs.gitlab.com/ja-jp/user/application_security/vulnerabilities/#create-a-gitlab-issue-for-a-vulnerability",[],"変更をより適切に追跡するためのイシューを作成する","ことでコラボレーションできます。",[12,1325,1326,1327,1332,1333,1338],{},"脆弱性のページから、AI搭載の各機能が集約された",[41,1328,1331],{"href":1329,"rel":1330},"https://about.gitlab.com/ja-jp/gitlab-duo-agent-platform/",[],"GitLab\nDuo","を活用して脆弱性を説明し、",[41,1334,1337],{"href":1335,"rel":1336},"https://docs.gitlab.com/ja-jp/user/application_security/vulnerabilities/#vulnerability-resolution",[],"脆弱性を解決するマージリクエストを自動的に作成する","こともできます。",[12,1340,1341,1342,1347],{},"GitLab\nDuoの",[41,1343,1346],{"href":1344,"rel":1345},"https://docs.gitlab.com/ja-jp/user/application_security/vulnerabilities/#vulnerability-explanation",[],"脆弱性の説明","は、大規模な言語モデルを使用して次を行います。",[19,1349,1350,1353,1356],{},[22,1351,1352],{},"脆弱性を要約する",[22,1354,1355],{},"脆弱性について、どのように悪用される可能性があるか、どのように修正するかをデベロッパーやセキュリティアナリストが理解できるようにする",[22,1357,1358],{},"緩和策を推奨する",[12,1360,1361],{},[180,1362],{"alt":1363,"src":1364},"SQLインジェクションGitLab Duo\nAIの説明","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/13-Explain-Vulnerability.png",[35,1366,1368],{"id":1367},"gitlab-ultimateのセキュリティ追加機能","GitLab Ultimateのセキュリティ追加機能",[12,1370,1371],{},"GitLab Ultimateには、GitHub Advanced\nSecurityにはない多くのセキュリティ機能を搭載しています。追加のセキュリティ機能の例として、ソフトウェア開発ライフサイクル（SDLC）全体のための追加のセキュリティスキャナー、きめ細かいセキュリティガードレール、カスタム権限などが挙げられます。",[48,1373,1375],{"id":1374},"sdlc全体のセキュリティスキャナー","SDLC全体のセキュリティスキャナー",[12,1377,1378],{},"当社のセキュリティスキャナーのポートフォリオは、SDLC全体に対応しています。",[1131,1380,1381,1394],{},[1134,1382,1383],{},[1137,1384,1385,1388,1391],{},[1140,1386,1387],{},"スキャナー名",[1140,1389,1390],{},"スキャン",[1140,1392,1393],{},"スキャンされた言語/ファイル",[1147,1395,1396,1410,1424,1439,1454,1469,1484],{},[1137,1397,1398,1404,1407],{},[1152,1399,1400],{},[41,1401,1403],{"href":62,"rel":1402},[],"静的アプリケーションセキュリティテスト（SAST）",[1152,1405,1406],{},"静的ソースコード",[1152,1408,1409],{},"C/C++、Java、Python、Go、JavaScript、C#など",[1137,1411,1412,1418,1421],{},[1152,1413,1414],{},[41,1415,1417],{"href":95,"rel":1416},[],"動的アプリケーションセキュリティテスト（DAST）",[1152,1419,1420],{},"Webアプリケーション、ライブAPIの実行",[1152,1422,1423],{},"言語に依存しない",[1137,1425,1426,1433,1436],{},[1152,1427,1428],{},[41,1429,1432],{"href":1430,"rel":1431},"https://docs.gitlab.com/ja-jp/user/application_security/iac_scanning/",[],"Infrastructure as Code（IaC）のスキャン",[1152,1434,1435],{},"IaCファイル",[1152,1437,1438],{},"Terraform、AWS Cloud Formation、Ansibleなど",[1137,1440,1441,1448,1451],{},[1152,1442,1443],{},[41,1444,1447],{"href":1445,"rel":1446},"https://docs.gitlab.com/ja-jp/user/application_security/container_scanning/",[],"コンテナのスキャン",[1152,1449,1450],{},"静的および実行中のコンテナイメージ",[1152,1452,1453],{},"Dockerfile",[1137,1455,1456,1463,1466],{},[1152,1457,1458],{},[41,1459,1462],{"href":1460,"rel":1461},"https://docs.gitlab.com/ja-jp/user/application_security/dependency_scanning/",[],"依存関係のスキャンとライセンスのスキャン",[1152,1464,1465],{},"アプリケーションの依存関係",[1152,1467,1468],{},"Requirements.txt、Yarn、Gradle、Npmなど",[1137,1470,1471,1478,1481],{},[1152,1472,1473],{},[41,1474,1477],{"href":1475,"rel":1476},"https://docs.gitlab.com/ja-jp/user/application_security/api_fuzzing/",[],"Web APIファズテスト",[1152,1479,1480],{},"ランダム/不正な形式のデータをweb-apiに送信",[1152,1482,1483],{},"OpenAPI、GraphQL、HAR、Postman Collection",[1137,1485,1486,1493,1496],{},[1152,1487,1488],{},[41,1489,1492],{"href":1490,"rel":1491},"https://docs.gitlab.com/ja-jp/user/application_security/coverage_fuzzing/",[],"カバレッジガイド付きファズテスト",[1152,1494,1495],{},"ランダム/不正な形式のデータを関数に送信",[1152,1497,1498],{},"C/C++、Go、Swift、Python、Rust、Java、JavaScript、AFL",[12,1500,1501,1502,656,1507,1512,1513,138],{},"GitLabでは、",[41,1503,1506],{"href":1504,"rel":1505},"https://about.gitlab.com/blog/integrate-external-security-scanners-into-your-devsecops-workflow/",[],"サードパーティのスキャナー（英語）",[41,1508,1511],{"href":1509,"rel":1510},"https://about.gitlab.com/blog/how-to-integrate-custom-security-scanners-into-gitlab/",[],"カスタムスキャナー（英語）","をプラットフォームに統合することもできます。スキャナーの結果は、パイプラインビュー、マージリクエストウィジェット、セキュリティダッシュボードなど、GitLabのさまざまな場所に自動的に表示されます。詳細については、",[41,1514,1517],{"href":1515,"rel":1516},"https://docs.gitlab.com/ja-jp/development/integrations/secure/",[],"セキュリティスキャナー統合ドキュメント",[48,1519,1520],{"id":1520},"きめ細かいセキュリティとコンプライアンスポリシー",[12,1522,1523,1524,1529],{},"GitLabのポリシーは、セキュリティとコンプライアンスの両チームに",[41,1525,1528],{"href":1526,"rel":1527},"https://about.gitlab.com/blog/meet-regulatory-standards-with-gitlab/",[],"組織内でグローバルに制御を実施する方法（英語）","を提供します。セキュリティチームは次のことを保証できます。",[19,1531,1532,1535,1538],{},[22,1533,1534],{},"適切な設定で開発チームのパイプラインにセキュリティスキャナーを実施",[22,1536,1537],{},"すべてのスキャンジョブは、変更や修正なしで実行",[22,1539,1540],{},"これらの調査結果に基づき、マージリクエストに対して適切な承認を提供",[12,1542,1543],{},[180,1544],{"alt":1545,"src":1546},"マージリクエストのセキュリティポリシー","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/14-MR-Policy.png",[12,1548,1549,1550,138],{},"コンプライアンスチームは、すべてのマージリクエストに対して複数の承認者を必須とし、マージリクエストやリポジトリの設定を有効化またはロックするなど、組織の要件に基づくプロジェクトでさまざまな設定が有効になっていることを確認できます。詳細については、",[41,1551,1553],{"href":110,"rel":1552},[],"GitLabセキュリティポリシーのドキュメント",[48,1555,1556],{"id":1556},"カスタムロールときめ細かい権限",[12,1558,1559,1564],{},[41,1560,1563],{"href":1561,"rel":1562},"https://about.gitlab.com/blog/how-to-tailor-gitlab-access-with-custom-roles/",[],"GitLab\nUltimateはカスタムロールを提供します（英語）","。これにより、組織はニーズに見合った正確な特権と権限を持つユーザーロールを作成できます。",[12,1566,1567],{},"たとえば、ユーザーはシステム内のセキュリティの脆弱性を表示する権限を持つ「セキュリティ監査担当者」ロールを作成できますが、この権限ではソースコードを表示したり、リポジトリ内で変更を実行したりできないよう設定できます。このきめ細かい権限設定により、職務の棲み分けを明確にできます。",[12,1569,1570],{},[180,1571],{"alt":1572,"src":1573},"カスタムロールの作成","https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/15-Custom-Roles.png",[12,1575,1192,1576,1581,1582,138],{},[41,1577,1580],{"href":1578,"rel":1579},"https://docs.gitlab.com/ja-jp/user/custom_roles/",[],"カスタムロール","および",[41,1583,1586],{"href":1584,"rel":1585},"https://docs.gitlab.com/ja-jp/user/custom_roles/abilities/",[],"利用可能な詳細な権限のドキュメント",[48,1588,130],{"id":130},[12,1590,1591],{},"コンプライアンスチームが、コンプライアンス基準の遵守状況や違反についての報告、グループのコンプライアンスフレームワークの管理などを一括して行う場所がコンプライアンスセンターです。コンプライアンスセンターには次の内容があります。",[19,1593,1594,1602,1610,1618],{},[22,1595,1596,1601],{},[41,1597,1600],{"href":1598,"rel":1599},"https://docs.gitlab.com/ja-jp/user/compliance/compliance_center/compliance_standards_adherence_dashboard/",[],"コンプライアンス基準遵守ダッシュボード","は、GitLab標準に準拠したプロジェクトの遵守状況を一覧表示します。",[22,1603,1604,1609],{},[41,1605,1608],{"href":1606,"rel":1607},"https://docs.gitlab.com/ja-jp/user/compliance/compliance_center/compliance_violations_report/",[],"コンプライアンス違反の報告","は、グループ内のすべてのプロジェクトのマージリクエストアクティビティの概要を表示します。",[22,1611,1612,1617],{},[41,1613,1616],{"href":1614,"rel":1615},"https://docs.gitlab.com/ja-jp/user/compliance/compliance_center/compliance_frameworks_report/",[],"コンプライアンスフレームワークのレポート","は、グループ内のコンプライアンスに関するすべてのフレームワークを表示します。",[22,1619,1620,1625],{},[41,1621,1624],{"href":1622,"rel":1623},"https://docs.gitlab.com/ja-jp/user/compliance/compliance_center/compliance_projects_report/",[],"コンプライアンスプロジェクトのレポート","は、グループ内のプロジェクトに適用されるコンプライアンスのフレームワークを表示します。",[12,1627,1628],{},[180,1629],{"alt":130,"src":1630},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749674404/Blog/Content%20Images/16-Compliance-Center.png",[12,1632,1633,1634,138],{},"これらのダッシュボードは、組織内のコンプライアンスを最適化するために、職務の棲み分けがきちんと守られているかを確認する上で有益です。詳細については、",[41,1635,1637],{"href":128,"rel":1636},[],"コンプライアンスセンターのドキュメント",[35,1639,1640],{"id":1640},"続きを読む",[12,1642,1643],{},"この記事では、GitLab Ultimateが提供する幅広いセキュリティ機能の一部についてのみ説明しています。GitLab\nUltimateが組織のセキュリティとデベロッパーの効率を向上させる方法について、詳しくは次のリソースを参照してください。",[19,1645,1646,1652,1659,1666,1673,1680,1687,1694],{},[22,1647,1648],{},[41,1649,1651],{"href":43,"rel":1650},[],"Ultimateを選ぶ理由",[22,1653,1654],{},[41,1655,1658],{"href":1656,"rel":1657},"https://gitlab-da.gitlab.io/tutorials/security-and-governance/devsecops/simply-vulnerable-notes/",[],"DevSecOpsチュートリアルを始める",[22,1660,1661],{},[41,1662,1665],{"href":1663,"rel":1664},"https://gitlab.com/gitlab-da/tutorials/security-and-governance/devsecops/simply-vulnerable-notes",[],"DevSecOpsサンプルプロジェクトの始め方",[22,1667,1668],{},[41,1669,1672],{"href":1670,"rel":1671},"https://docs.gitlab.com/ja-jp/user/project/import/github/",[],"プロジェクトをGitHubからGitLabドキュメントにインポートする",[22,1674,1675],{},[41,1676,1679],{"href":1677,"rel":1678},"https://docs.gitlab.com/ja-jp/ci/migration/github_actions/",[],"GitHub\nActionsドキュメントからの移行",[22,1681,1682],{},[41,1683,1686],{"href":1684,"rel":1685},"https://docs.gitlab.com/ja-jp/ci/quick_start/",[],"チュートリアル：最初のGitLab\nCI/CDパイプラインを作成して実行する",[22,1688,1689],{},[41,1690,1693],{"href":1691,"rel":1692},"https://docs.gitlab.com/ja-jp/ci/quick_start/tutorial/",[],"チュートリアル：複雑なパイプラインを作成する",[22,1695,1696],{},[41,1697,1700],{"href":1698,"rel":1699},"https://docs.gitlab.com/ja-jp/ci/yaml/",[],"CI/CD YAML構文リファレンス",[12,1702,1703,1704,1709],{},"*監修：小松原 つかさ ",[41,1705,1708],{"href":1706,"rel":1707},"https://gitlab.com/tkomatsubara",[],"@tkomatsubara",[1710,1711],"br",{},[12,1713,1714],{},"（GitLab合同会社 ソリューションアーキテクト本部 シニアパートナーソリューションアーキテクト）",[1716,1717,1718],"style",{},"html pre.shiki code .shJU0, html code.shiki .shJU0{--shiki-default:#22863A}html pre.shiki code .sgsFI, html code.shiki .sgsFI{--shiki-default:#24292E}html pre.shiki code .sYBdl, html code.shiki .sYBdl{--shiki-default:#032F62}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html pre.shiki code .sD7c4, html code.shiki .sD7c4{--shiki-default:#D73A49}html pre.shiki code .sAwPA, html code.shiki .sAwPA{--shiki-default:#6A737D}html pre.shiki code .sYu0t, html code.shiki .sYu0t{--shiki-default:#005CC5}",{"title":362,"searchDepth":380,"depth":380,"links":1720},[1721,1725,1726,1732,1738],{"id":37,"depth":380,"text":24,"children":1722},[1723,1724],{"id":50,"depth":509,"text":51},{"id":83,"depth":509,"text":84},{"id":141,"depth":380,"text":27},{"id":311,"depth":380,"text":311,"children":1727},[1728,1729,1730,1731],{"id":328,"depth":509,"text":328},{"id":664,"depth":509,"text":664},{"id":982,"depth":509,"text":982},{"id":1200,"depth":509,"text":1200},{"id":1367,"depth":380,"text":1368,"children":1733},[1734,1735,1736,1737],{"id":1374,"depth":509,"text":1375},{"id":1520,"depth":509,"text":1520},{"id":1556,"depth":509,"text":1556},{"id":130,"depth":509,"text":130},{"id":1640,"depth":380,"text":1640},"2024-05-01","GitLab UltimateとGitHub Advanced Securityの共通点と違いを理解し、GitLab DevSecOpsプラットフォームへの移行を段階的に進めるための詳細ガイドです。","md",null,"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749666187/Blog/Hero%20Images/blog-image-template-1800x945__6_.png",{},"/ja-jp/blog/migration-guide-github-advanced-security-to-gitlab-ultimate",{"ogTitle":5,"ogImage":1743,"ogDescription":1740,"ogSiteName":1747,"noIndex":1748,"ogType":1749,"ogUrl":1750,"title":5,"canonicalUrls":1750,"description":1740},"https://about.gitlab.com",false,"article","https://about.gitlab.com/blog/migration-guide-github-advanced-security-to-gitlab-ultimate","migration-guide-github-advanced-security-to-gitlab-ultimate","ja-jp/blog/migration-guide-github-advanced-security-to-gitlab-ultimate",[1754,1755,732,1756,1757],"tutorial","zero trust","DevSecOps platform","testing","BlogPost","2024-12-25","f1W6e53jCNMp7rMKrHDUVQ-_pLHu3EgXPq81W9QBAOw",{"logo":1762,"freeTrial":1767,"sales":1772,"login":1777,"items":1782,"search":2111,"minimal":2144,"duo":2161,"switchNav":2170,"pricingDeployment":2181},{"config":1763},{"href":1764,"dataGaName":1765,"dataGaLocation":1766},"/ja-jp/","gitlab logo","header",{"text":1768,"config":1769},"無料トライアルを開始",{"href":1770,"dataGaName":1771,"dataGaLocation":1766},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/ja-jp&glm_content=default-saas-trial/","free trial",{"text":1773,"config":1774},"デモをリクエスト",{"href":1775,"dataGaName":1776,"dataGaLocation":1766},"/ja-jp/sales/?contact-topic=request-demo","sales",{"text":1778,"config":1779},"サインイン",{"href":1780,"dataGaName":1781,"dataGaLocation":1766},"https://gitlab.com/users/sign_in/","sign in",[1783,1812,1914,1919,2033,2089],{"text":1784,"config":1785,"menu":1787},"プラットフォーム",{"dataNavLevelOne":1786},"platform",{"type":1788,"columns":1789},"cards",[1790,1796,1804],{"title":1784,"description":1791,"link":1792},"DevSecOpsに特化したインテリジェントオーケストレーションプラットフォーム",{"text":1793,"config":1794},"プラットフォームの詳細はこちら",{"href":1795,"dataGaName":1786,"dataGaLocation":1766},"/ja-jp/platform/",{"title":1797,"description":1798,"link":1799},"GitLab Duo Agent Platform","ソフトウェアライフサイクル全体を支えるエージェント型AI",{"text":1800,"config":1801},"GitLab Duoのご紹介",{"href":1802,"dataGaName":1803,"dataGaLocation":1766},"/ja-jp/gitlab-duo-agent-platform/","gitlab duo agent platform",{"title":1805,"description":1806,"link":1807},"GitLabが選ばれる理由","エンタープライズがGitLabを選ぶ主な理由をご覧ください",{"text":1808,"config":1809},"詳細はこちら",{"href":1810,"dataGaName":1811,"dataGaLocation":1766},"/ja-jp/why-gitlab/","why gitlab",{"text":1813,"left":512,"config":1814,"menu":1816},"製品",{"dataNavLevelOne":1815},"solutions",{"type":1817,"link":1818,"columns":1822,"feature":1893},"lists",{"text":1819,"config":1820},"すべてのソリューションを表示",{"href":1821,"dataGaName":1815,"dataGaLocation":1766},"/ja-jp/solutions/",[1823,1848,1871],{"title":1824,"description":1825,"link":1826,"items":1831},"自動化","CI/CDと自動化でデプロイを加速",{"config":1827},{"icon":1828,"href":1829,"dataGaName":1830,"dataGaLocation":1766},"AutomatedCodeAlt","/ja-jp/solutions/delivery-automation/","automated software delivery",[1832,1836,1839,1844],{"text":1833,"config":1834},"CI/CD",{"href":1835,"dataGaLocation":1766,"dataGaName":1833},"/ja-jp/solutions/continuous-integration/",{"text":1797,"config":1837},{"href":1802,"dataGaLocation":1766,"dataGaName":1838},"gitlab duo agent platform - product menu",{"text":1840,"config":1841},"ソースコード管理",{"href":1842,"dataGaLocation":1766,"dataGaName":1843},"/ja-jp/solutions/source-code-management/","Source Code Management",{"text":1845,"config":1846},"自動化されたソフトウェアデリバリー",{"href":1829,"dataGaLocation":1766,"dataGaName":1847},"Automated software delivery",{"title":1849,"description":1850,"link":1851,"items":1856},"セキュリティ","セキュリティを犠牲にすることなくコード作成を高速化",{"config":1852},{"href":1853,"dataGaName":1854,"dataGaLocation":1766,"icon":1855},"/ja-jp/solutions/application-security-testing/","security and compliance","ShieldCheckLight",[1857,1861,1866],{"text":1858,"config":1859},"アプリケーションセキュリティテスト",{"href":1853,"dataGaName":1860,"dataGaLocation":1766},"Application security testing",{"text":1862,"config":1863},"ソフトウェアサプライチェーンセキュリティ",{"href":1864,"dataGaLocation":1766,"dataGaName":1865},"/ja-jp/solutions/supply-chain/","Software supply chain security",{"text":1867,"config":1868},"ソフトウェアコンプライアンス",{"href":1869,"dataGaName":1870,"dataGaLocation":1766},"/ja-jp/solutions/software-compliance/","software compliance",{"title":1872,"link":1873,"items":1878},"測定",{"config":1874},{"icon":1875,"href":1876,"dataGaName":1877,"dataGaLocation":1766},"DigitalTransformation","/ja-jp/solutions/visibility-measurement/","visibility and measurement",[1879,1883,1888],{"text":1880,"config":1881},"可視性と測定",{"href":1876,"dataGaLocation":1766,"dataGaName":1882},"Visibility and Measurement",{"text":1884,"config":1885},"バリューストリーム管理",{"href":1886,"dataGaLocation":1766,"dataGaName":1887},"/ja-jp/solutions/value-stream-management/","Value Stream Management",{"text":1889,"config":1890},"分析とインサイト",{"href":1891,"dataGaLocation":1766,"dataGaName":1892},"/ja-jp/solutions/analytics-and-insights/","Analytics and insights",{"title":1894,"type":1817,"items":1895},"GitLabが活躍する場所",[1896,1902,1908],{"text":1897,"config":1898},"大企業",{"icon":1899,"href":1900,"dataGaLocation":1766,"dataGaName":1901},"Building","/ja-jp/enterprise/","enterprise",{"text":1903,"config":1904},"スモールビジネス",{"icon":1905,"href":1906,"dataGaLocation":1766,"dataGaName":1907},"Work","/ja-jp/small-business/","small business",{"text":1909,"config":1910},"公共部門",{"icon":1911,"href":1912,"dataGaLocation":1766,"dataGaName":1913},"Organization","/ja-jp/solutions/public-sector/","public sector",{"text":1915,"config":1916},"価格",{"href":1917,"dataGaName":1918,"dataGaLocation":1766,"dataNavLevelOne":1918},"/ja-jp/pricing/","pricing",{"text":1920,"config":1921,"menu":1923},"関連リソース",{"dataNavLevelOne":1922},"resources",{"type":1817,"link":1924,"columns":1928,"feature":2022},{"text":1925,"config":1926},"すべてのリソースを表示",{"href":1927,"dataGaName":1922,"dataGaLocation":1766},"/ja-jp/resources/",[1929,1962,1989],{"title":1930,"items":1931},"はじめに",[1932,1937,1942,1947,1952,1957],{"text":1933,"config":1934},"インストール",{"href":1935,"dataGaName":1936,"dataGaLocation":1766},"/ja-jp/install/","install",{"text":1938,"config":1939},"クイックスタートガイド",{"href":1940,"dataGaName":1941,"dataGaLocation":1766},"/ja-jp/get-started/","quick setup checklists",{"text":1943,"config":1944},"学ぶ",{"href":1945,"dataGaLocation":1766,"dataGaName":1946},"https://university.gitlab.com/","learn",{"text":1948,"config":1949},"製品ドキュメント",{"href":1950,"dataGaName":1951,"dataGaLocation":1766},"https://docs.gitlab.com/ja-jp/","product documentation",{"text":1953,"config":1954},"ベストプラクティスビデオ",{"href":1955,"dataGaName":1956,"dataGaLocation":1766},"/ja-jp/getting-started-videos/","best practice videos",{"text":1958,"config":1959},"インテグレーション",{"href":1960,"dataGaName":1961,"dataGaLocation":1766},"/ja-jp/integrations/","integrations",{"title":1963,"items":1964},"検索する",[1965,1970,1975,1980,1984],{"text":1966,"config":1967},"お客様成功事例",{"href":1968,"dataGaName":1969,"dataGaLocation":1766},"/ja-jp/customers/","customer success stories",{"text":1971,"config":1972},"ブログ",{"href":1973,"dataGaName":1974,"dataGaLocation":1766},"/ja-jp/blog/","blog",{"text":1976,"config":1977},"Demo Hub",{"href":1978,"dataGaName":1979,"dataGaLocation":1766},"/ja-jp/demo-hub/","demo hub",{"text":1981,"config":1982},"The Source",{"href":1983,"dataGaName":1974,"dataGaLocation":1766},"/ja-jp/the-source/",{"text":1985,"config":1986},"リモート",{"href":1987,"dataGaName":1988,"dataGaLocation":1766},"https://handbook.gitlab.com/handbook/company/culture/all-remote/","remote",{"title":1990,"items":1991},"つなげる",[1992,1997,2002,2007,2012,2017],{"text":1993,"config":1994},"GitLabサービス",{"href":1995,"dataGaName":1996,"dataGaLocation":1766},"/ja-jp/services/","services",{"text":1998,"config":1999},"コントリビュート",{"href":2000,"dataGaName":2001,"dataGaLocation":1766},"https://contributors.gitlab.com","contribute",{"text":2003,"config":2004},"コミュニティ",{"href":2005,"dataGaName":2006,"dataGaLocation":1766},"/community/","community",{"text":2008,"config":2009},"フォーラム",{"href":2010,"dataGaName":2011,"dataGaLocation":1766},"https://forum.gitlab.com/","forum",{"text":2013,"config":2014},"イベント",{"href":2015,"dataGaName":2016,"dataGaLocation":1766},"/events/","events",{"text":2018,"config":2019},"パートナー",{"href":2020,"dataGaName":2021,"dataGaLocation":1766},"/ja-jp/partners/","partners",{"config":2023,"title":2026,"text":2027,"link":2028},{"background":2024,"textColor":2025},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1777322348/qpq8yrgn8knii57omj0c.png')","#000","GitLabの最新情報","最新の機能と改善点に関する情報をお届けします。",{"text":2029,"config":2030},"最新情報を読む",{"href":2031,"dataGaName":2032,"dataGaLocation":1766},"/ja-jp/whats-new/","whats new",{"text":2034,"config":2035,"menu":2037},"企業情報",{"dataNavLevelOne":2036},"company",{"type":1817,"columns":2038},[2039],{"items":2040},[2041,2046,2052,2054,2059,2064,2069,2074,2079,2084],{"text":2042,"config":2043},"GitLabについて",{"href":2044,"dataGaName":2045,"dataGaLocation":1766},"/ja-jp/company/","about",{"text":2047,"config":2048,"footerGa":2051},"採用情報",{"href":2049,"dataGaName":2050,"dataGaLocation":1766},"/jobs/","jobs",{"dataGaName":2050},{"text":2013,"config":2053},{"href":2015,"dataGaName":2016,"dataGaLocation":1766},{"text":2055,"config":2056},"経営陣",{"href":2057,"dataGaName":2058,"dataGaLocation":1766},"/company/team/e-group/","leadership",{"text":2060,"config":2061},"ハンドブック",{"href":2062,"dataGaName":2063,"dataGaLocation":1766},"https://handbook.gitlab.com/","handbook",{"text":2065,"config":2066},"投資家向け情報",{"href":2067,"dataGaName":2068,"dataGaLocation":1766},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":2070,"config":2071},"トラストセンター",{"href":2072,"dataGaName":2073,"dataGaLocation":1766},"/ja-jp/security/","trust center",{"text":2075,"config":2076},"AI Transparency Center",{"href":2077,"dataGaName":2078,"dataGaLocation":1766},"/ja-jp/ai-transparency-center/","ai transparency center",{"text":2080,"config":2081},"ニュースレター",{"href":2082,"dataGaName":2083,"dataGaLocation":1766},"/company/contact/#contact-forms","newsletter",{"text":2085,"config":2086},"プレス",{"href":2087,"dataGaName":2088,"dataGaLocation":1766},"/press/","press",{"text":2090,"config":2091,"menu":2092},"お問い合わせ",{"dataNavLevelOne":2036},{"type":1817,"columns":2093},[2094],{"items":2095},[2096,2101,2106],{"text":2097,"config":2098},"お問い合わせはこちら",{"href":2099,"dataGaName":2100,"dataGaLocation":1766},"/ja-jp/sales/","talk to sales",{"text":2102,"config":2103},"サポートを受ける",{"href":2104,"dataGaName":2105,"dataGaLocation":1766},"https://support.gitlab.com/hc/en-us","support portal",{"text":2107,"config":2108},"カスタマーポータル",{"href":2109,"dataGaName":2110,"dataGaLocation":1766},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":2112,"login":2113,"suggestions":2120},"閉じる",{"text":2114,"link":2115},"リポジトリとプロジェクトを検索するには、次にログインします",{"text":2116,"config":2117},"GitLab.com",{"href":1780,"dataGaName":2118,"dataGaLocation":2119},"search login","search",{"text":2121,"default":2122},"提案",[2123,2125,2130,2132,2136,2140],{"text":1797,"config":2124},{"href":1802,"dataGaName":1797,"dataGaLocation":2119},{"text":2126,"config":2127},"コード提案（AI）",{"href":2128,"dataGaName":2129,"dataGaLocation":2119},"/ja-jp/solutions/code-suggestions/","Code Suggestions (AI)",{"text":1833,"config":2131},{"href":1835,"dataGaName":1833,"dataGaLocation":2119},{"text":2133,"config":2134},"GitLab on AWS",{"href":2135,"dataGaName":2133,"dataGaLocation":2119},"/ja-jp/partners/technology-partners/aws/",{"text":2137,"config":2138},"GitLab on Google Cloud",{"href":2139,"dataGaName":2137,"dataGaLocation":2119},"/ja-jp/partners/technology-partners/google-cloud-platform/",{"text":2141,"config":2142},"GitLabを選ぶ理由",{"href":1810,"dataGaName":2143,"dataGaLocation":2119},"Why GitLab?",{"freeTrial":2145,"mobileIcon":2149,"desktopIcon":2154,"secondaryButton":2157},{"text":1768,"config":2146},{"href":2147,"dataGaName":1771,"dataGaLocation":2148},"https://gitlab.com/-/trials/new/","nav",{"altText":2150,"config":2151},"GitLabアイコン",{"src":2152,"dataGaName":2153,"dataGaLocation":2148},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":2150,"config":2155},{"src":2156,"dataGaName":2153,"dataGaLocation":2148},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":1930,"config":2158},{"href":2159,"dataGaName":2160,"dataGaLocation":2148},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/ja-jp/get-started/","get started",{"freeTrial":2162,"mobileIcon":2166,"desktopIcon":2168},{"text":2163,"config":2164},"GitLab Duoの詳細について",{"href":1802,"dataGaName":2165,"dataGaLocation":2148},"gitlab duo",{"altText":2150,"config":2167},{"src":2152,"dataGaName":2153,"dataGaLocation":2148},{"altText":2150,"config":2169},{"src":2156,"dataGaName":2153,"dataGaLocation":2148},{"button":2171,"mobileIcon":2176,"desktopIcon":2178},{"text":2172,"config":2173},"/switch",{"href":2174,"dataGaName":2175,"dataGaLocation":2148},"#contact","switch",{"altText":2150,"config":2177},{"src":2152,"dataGaName":2153,"dataGaLocation":2148},{"altText":2150,"config":2179},{"src":2180,"dataGaName":2153,"dataGaLocation":2148},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":2182,"mobileIcon":2187,"desktopIcon":2189},{"text":2183,"config":2184},"料金ページに戻る",{"href":1917,"dataGaName":2185,"dataGaLocation":2148,"icon":2186},"back to pricing","GoBack",{"altText":2150,"config":2188},{"src":2152,"dataGaName":2153,"dataGaLocation":2148},{"altText":2150,"config":2190},{"src":2156,"dataGaName":2153,"dataGaLocation":2148},{"title":2192,"button":2193,"config":2197},"GitLab Orbitが登場: AIエージェントのためのコンテキストレイヤー",{"text":1808,"config":2194},{"href":2195,"dataGaName":2196,"dataGaLocation":1766},"/ja-jp/gitlab-orbit/","orbit",{"layout":2198,"disabled":1748},"release",{"data":2200},{"text":2201,"source":2202,"edit":2208,"contribute":2213,"config":2218,"items":2223,"minimal":2431},"GitはSoftware Freedom Conservancyの商標です。当社は「GitLab」をライセンスに基づいて使用しています",{"text":2203,"config":2204},"ページのソースを表示",{"href":2205,"dataGaName":2206,"dataGaLocation":2207},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":2209,"config":2210},"このページを編集",{"href":2211,"dataGaName":2212,"dataGaLocation":2207},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":2214,"config":2215},"ご協力をお願いします",{"href":2216,"dataGaName":2217,"dataGaLocation":2207},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":2219,"facebook":2220,"youtube":2221,"linkedin":2222},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[2224,2268,2321,2364,2398],{"title":1915,"links":2225,"subMenu":2239},[2226,2230,2235],{"text":2227,"config":2228},"プランの表示",{"href":1917,"dataGaName":2229,"dataGaLocation":2207},"view plans",{"text":2231,"config":2232},"Premiumを選ぶ理由",{"href":2233,"dataGaName":2234,"dataGaLocation":2207},"/ja-jp/pricing/premium/","why premium",{"text":1651,"config":2236},{"href":2237,"dataGaName":2238,"dataGaLocation":2207},"/ja-jp/pricing/ultimate/","why ultimate",[2240],{"title":2090,"links":2241},[2242,2244,2246,2248,2253,2258,2263],{"text":2090,"config":2243},{"href":2099,"dataGaName":1776,"dataGaLocation":2207},{"text":2102,"config":2245},{"href":2104,"dataGaName":2105,"dataGaLocation":2207},{"text":2107,"config":2247},{"href":2109,"dataGaName":2110,"dataGaLocation":2207},{"text":2249,"config":2250},"ステータス",{"href":2251,"dataGaName":2252,"dataGaLocation":2207},"https://status.gitlab.com/","status",{"text":2254,"config":2255},"利用規約",{"href":2256,"dataGaName":2257,"dataGaLocation":2207},"/terms/","terms of use",{"text":2259,"config":2260},"プライバシーに関する声明",{"href":2261,"dataGaName":2262,"dataGaLocation":2207},"/ja-jp/privacy/","privacy statement",{"text":2264,"config":2265},"Cookie 優先設定",{"dataGaName":2266,"dataGaLocation":2207,"id":2267,"isOneTrustButton":512},"cookie preferences","ot-sdk-btn",{"title":1813,"links":2269,"subMenu":2278},[2270,2274],{"text":2271,"config":2272},"DevSecOpsプラットフォーム",{"href":1795,"dataGaName":2273,"dataGaLocation":2207},"devsecops platform",{"text":2275,"config":2276},"AI支援開発",{"href":1802,"dataGaName":2277,"dataGaLocation":2207},"ai-assisted development",[2279],{"title":2280,"links":2281},"トピック",[2282,2286,2291,2296,2301,2306,2311,2316],{"text":1833,"config":2283},{"href":2284,"dataGaName":2285,"dataGaLocation":2207},"/ja-jp/topics/ci-cd/","cicd",{"text":2287,"config":2288},"GitOps",{"href":2289,"dataGaName":2290,"dataGaLocation":2207},"/ja-jp/topics/gitops/","gitops",{"text":2292,"config":2293},"DevOps",{"href":2294,"dataGaName":2295,"dataGaLocation":2207},"/ja-jp/topics/devops/","devops",{"text":2297,"config":2298},"バージョン管理",{"href":2299,"dataGaName":2300,"dataGaLocation":2207},"/ja-jp/topics/version-control/","version control",{"text":2302,"config":2303},"DevSecOps",{"href":2304,"dataGaName":2305,"dataGaLocation":2207},"/ja-jp/topics/devsecops/","devsecops",{"text":2307,"config":2308},"クラウドネイティブ",{"href":2309,"dataGaName":2310,"dataGaLocation":2207},"/ja-jp/topics/cloud-native/","cloud native",{"text":2312,"config":2313},"コーディングのためのAI",{"href":2314,"dataGaName":2315,"dataGaLocation":2207},"/ja-jp/topics/devops/ai-for-coding/","ai for coding",{"text":2317,"config":2318},"エージェント型AI",{"href":2319,"dataGaName":2320,"dataGaLocation":2207},"/ja-jp/topics/agentic-ai/","agentic ai",{"title":2322,"links":2323},"ソリューション",[2324,2327,2329,2334,2338,2341,2344,2347,2349,2351,2354,2359],{"text":1858,"config":2325},{"href":1853,"dataGaName":2326,"dataGaLocation":2207},"Application Security Testing",{"text":1845,"config":2328},{"href":1829,"dataGaName":1830,"dataGaLocation":2207},{"text":2330,"config":2331},"アジャイル開発",{"href":2332,"dataGaName":2333,"dataGaLocation":2207},"/ja-jp/solutions/agile-delivery/","agile delivery",{"text":2335,"config":2336},"SCM",{"href":1842,"dataGaName":2337,"dataGaLocation":2207},"source code management",{"text":1833,"config":2339},{"href":1835,"dataGaName":2340,"dataGaLocation":2207},"continuous integration & delivery",{"text":1884,"config":2342},{"href":1886,"dataGaName":2343,"dataGaLocation":2207},"value stream management",{"text":2287,"config":2345},{"href":2346,"dataGaName":2290,"dataGaLocation":2207},"/ja-jp/solutions/gitops/",{"text":1897,"config":2348},{"href":1900,"dataGaName":1901,"dataGaLocation":2207},{"text":1903,"config":2350},{"href":1906,"dataGaName":1907,"dataGaLocation":2207},{"text":2352,"config":2353},"公共機関",{"href":1912,"dataGaName":1913,"dataGaLocation":2207},{"text":2355,"config":2356},"教育",{"href":2357,"dataGaName":2358,"dataGaLocation":2207},"/ja-jp/solutions/education/","education",{"text":2360,"config":2361},"金融サービス",{"href":2362,"dataGaName":2363,"dataGaLocation":2207},"/ja-jp/solutions/finance/","financial services",{"title":2365,"links":2366},"リソース",[2367,2369,2371,2373,2377,2379,2382,2384,2386,2388,2390,2392,2394,2396],{"text":1933,"config":2368},{"href":1935,"dataGaName":1936,"dataGaLocation":2207},{"text":1938,"config":2370},{"href":1940,"dataGaName":1941,"dataGaLocation":2207},{"text":1943,"config":2372},{"href":1945,"dataGaName":1946,"dataGaLocation":2207},{"text":1948,"config":2374},{"href":2375,"dataGaName":2376,"dataGaLocation":2207},"https://docs.gitlab.com/ja-jp","docs",{"text":1971,"config":2378},{"href":1973,"dataGaName":1974,"dataGaLocation":2207},{"text":2380,"config":2381},"最新リリース",{"href":2031,"dataGaName":2032,"dataGaLocation":2207},{"text":1966,"config":2383},{"href":1968,"dataGaName":1969,"dataGaLocation":2207},{"text":1985,"config":2385},{"href":1987,"dataGaName":1988,"dataGaLocation":2207},{"text":1993,"config":2387},{"href":1995,"dataGaName":1996,"dataGaLocation":2207},{"text":1998,"config":2389},{"href":2000,"dataGaName":2001,"dataGaLocation":2207},{"text":2003,"config":2391},{"href":2005,"dataGaName":2006,"dataGaLocation":2207},{"text":2008,"config":2393},{"href":2010,"dataGaName":2011,"dataGaLocation":2207},{"text":2013,"config":2395},{"href":2015,"dataGaName":2016,"dataGaLocation":2207},{"text":2018,"config":2397},{"href":2020,"dataGaName":2021,"dataGaLocation":2207},{"title":2399,"links":2400},"会社情報",[2401,2403,2405,2407,2409,2411,2415,2420,2422,2424,2426],{"text":2042,"config":2402},{"href":2044,"dataGaName":2036,"dataGaLocation":2207},{"text":2047,"config":2404},{"href":2049,"dataGaName":2050,"dataGaLocation":2207},{"text":2055,"config":2406},{"href":2057,"dataGaName":2058,"dataGaLocation":2207},{"text":2060,"config":2408},{"href":2062,"dataGaName":2063,"dataGaLocation":2207},{"text":2065,"config":2410},{"href":2067,"dataGaName":2068,"dataGaLocation":2207},{"text":2412,"config":2413},"Sustainability",{"href":2414,"dataGaName":2412,"dataGaLocation":2207},"/sustainability/",{"text":2416,"config":2417},"ダイバーシティ、インクルージョン、ビロンギング（DIB）",{"href":2418,"dataGaName":2419,"dataGaLocation":2207},"/ja-jp/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":2070,"config":2421},{"href":2072,"dataGaName":2073,"dataGaLocation":2207},{"text":2080,"config":2423},{"href":2082,"dataGaName":2083,"dataGaLocation":2207},{"text":2085,"config":2425},{"href":2087,"dataGaName":2088,"dataGaLocation":2207},{"text":2427,"config":2428},"現代奴隷制の透明性に関する声明",{"href":2429,"dataGaName":2430,"dataGaLocation":2207},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":2432},[2433,2435,2438],{"text":2254,"config":2434},{"href":2256,"dataGaName":2257,"dataGaLocation":2207},{"text":2436,"config":2437},"Cookieの設定",{"dataGaName":2266,"dataGaLocation":2207,"id":2267,"isOneTrustButton":512},{"text":2259,"config":2439},{"href":2261,"dataGaName":2262,"dataGaLocation":2207},[2441],{"id":2442,"title":7,"body":1742,"config":2443,"content":2445,"description":1742,"extension":2449,"meta":2450,"navigation":512,"path":2451,"seo":2452,"stem":2453,"__hash__":2454},"blogAuthors/en-us/blog/authors/fernando-diaz.yml",{"template":2444},"BlogAuthor",{"name":7,"config":2446},{"headshot":2447,"ctfId":2448},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1749659556/Blog/Author%20Headshots/fern_diaz.png","fjdiaz","yml",{},"/en-us/blog/authors/fernando-diaz",{},"en-us/blog/authors/fernando-diaz","lxRJIOydP4_yzYZvsPcuQevP9AYAKREF7i8QmmdnOWc",[2456,2465,2473],{"title":2457,"description":2458,"heroImage":2459,"category":732,"date":2460,"authors":2461,"slug":2464,"externalUrl":1742},"GitLab Secrets ManagerがESO、Terraform、APIに対応","スタック全体の認証情報管理をシンプルに。GitLab Secrets Managerは External Secrets Operator（ESO）、Terraform、Secrets Manager APIに対応し、CI/CD以外の ワークフローからもシークレットを安全に取得できます。","https://res.cloudinary.com/about-gitlab-com/image/upload/v1759320418/xjmqcozxzt4frx0hori3.png","2026-08-06",[2462,2463],"Erick Bajao","Joe Randazzo","gitlab-secrets-manager-add-eso-terraform-api-support",{"title":2466,"description":2467,"heroImage":2468,"category":732,"date":2469,"authors":2470,"slug":2472,"externalUrl":1742},"Claudeが書き、GitLabがつなぐ：本番環境まで途切れないセキュリティ","Claude Securityはコーディングセッション内で脆弱性を検出します。そこから先はGitLabが引き継ぎ、スキャン、ポリシーの適用、そしてソフトウェアライフサイクル全体の監査エビデンス作成までを担います。","https://res.cloudinary.com/about-gitlab-com/image/upload/v1756122536/akivvcnafog9c4dhhzkp.png","2026-08-03",[2471],"Alisa Ho","claude-security-and-gitlab",{"title":2474,"description":2475,"heroImage":2476,"category":732,"date":2477,"authors":2478,"slug":2480,"externalUrl":1742},"GitLab Duoセキュリティレビューでスキャナーが見逃すロジックの欠陥を検出","AIによるセキュリティ推論で、コードレビューの段階のうちに認可の不備やビジネスロジックのエラー、レース条件を検出します。","https://res.cloudinary.com/about-gitlab-com/image/upload/v1783980535/t3gez0gpayfndrhncunf.png","2026-07-16",[2479],"Mark Settle","gitlab-duo-security-review-flow",{"promotions":2482},[2483,2497,2509,2520],{"id":2484,"categories":2485,"header":2487,"text":2488,"button":2489,"image":2494},"ai-modernization",[2486],"ai","AIの真価、組織全体で発揮できていますか？","所要時間は5分以内です",{"text":2490,"config":2491},"AI成熟度スコアを確認する",{"href":2492,"dataGaName":2493,"dataGaLocation":1974},"/ja-jp/assessments/ai-modernization-assessment/","modernization assessment",{"config":2495},{"src":2496},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/qix0m7kwnd8x2fh1zq49.png",{"id":2498,"categories":2499,"header":2501,"text":2488,"button":2502,"image":2506},"devops-modernization",[2500,2305],"product","単にツールを管理するだけでなく、イノベーションを提供していますか？",{"text":2503,"config":2504},"DevOps成熟度スコアを確認しましょう",{"href":2505,"dataGaName":2493,"dataGaLocation":1974},"/ja-jp/assessments/devops-modernization-assessment/",{"config":2507},{"src":2508},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138785/eg818fmakweyuznttgid.png",{"id":2510,"categories":2511,"header":2512,"text":2488,"button":2513,"image":2517},"security-modernization",[732],"スピードのためにセキュリティを犠牲にしていませんか？",{"text":2514,"config":2515},"セキュリティ成熟度スコアを確認しましょう",{"href":2516,"dataGaName":2493,"dataGaLocation":1974},"/ja-jp/assessments/security-modernization-assessment/",{"config":2518},{"src":2519},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1772138786/p4pbqd9nnjejg5ds6mdk.png",{"id":2521,"paths":2522,"header":2525,"text":2526,"button":2527,"image":2532},"github-azure-migration",[2523,2524],"migration-from-azure-devops-to-gitlab","integrating-azure-devops-scm-and-gitlab","チームはGitHubのAzure移行に対応できていますか？","GitHubはすでにAzureを基盤として再構築を進めています。それがあなたのチームにとって何を意味するのか、ご確認ください。",{"text":2528,"config":2529},"GitLabとGitHubの比較を見る",{"href":2530,"dataGaName":2531,"dataGaLocation":1974},"/ja-jp/compare/gitlab-vs-github/github-azure-migration/","github azure migration",{"config":2533},{"src":2508},{"header":2535,"blurb":2536,"button":2537,"secondaryButton":2541},"今すぐ開発をスピードアップ","DevSecOpsに特化したインテリジェントオーケストレーションプラットフォームで実現できることをご確認ください。\n",{"text":1768,"config":2538},{"href":2539,"dataGaName":1771,"dataGaLocation":2540},"https://gitlab.com/-/trial_registrations/new?glm_content=default-saas-trial&glm_source=about.gitlab.com/ja-jp/","feature",{"text":2090,"config":2542},{"href":2099,"dataGaName":1776,"dataGaLocation":2540},1786803792483]