Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Building GitLab with GitLab: Web API Fuzz Testing

Blog post from GitLab

Post Details
Company
Date Published
Author
Mike Eddington and Eugene Lim
Word Count
1,581
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab's initiative to enhance its platform through internal testing, known as dogfooding, focuses on security testing with the API fuzzing project. The project aims to integrate Web API Fuzz Testing into the DevSecOps lifecycle, identifying bugs and potential security issues by generating unexpected inputs to a web API. GitLab built an OpenAPI specification for its endpoints using the grape-swagger gem, overcoming challenges with edge cases and wildcard parameters. Performance tuning involved splitting tests into multiple jobs and optimizing resources, while triaging hundreds of findings required careful analysis to distinguish true vulnerabilities from unexpected behavior. The project leveraged GitLab's features like Review Apps and dynamically generated pipelines to facilitate the workflow, resulting in improved API documentation and identification of key process pain points. Future efforts may involve moving to OpenAPI v3 and utilizing tools like the HAR Recorder to enhance the fuzzing process, with the workflow best suited to scheduled pipelines due to its high compute cost.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.