Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Detect application vulnerabilities with GitLab's browser-based DAST

Blog post from GitLab

Post Details
Company
Date Published
Author
Sara Meadzinger
Word Count
1,034
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

In GitLab 17.0, released in May 2024, the proxy-based dynamic application security testing (DAST) was replaced with GitLab's proprietary browser-based DAST tool, which automates penetration testing to identify vulnerabilities in web applications while they are running. This new DAST tool, which is language-agnostic, simulates real-world attacks and can detect critical vulnerabilities like cross-site scripting and SQL injection, offering enhanced security for modern applications compared to the legacy proxy-based DAST that relied on the Zed Attack Proxy project. The new DAST can be integrated into CI/CD pipelines for automated scans or used for on-demand scans, supporting complex application architectures and multi-step sign-in workflows with its headless browser capability. GitLab recommends using DAST alongside other security measures such as static application security testing (SAST) and container scanning to ensure comprehensive protection against vulnerabilities and misconfigurations. Users who wish to continue using the legacy proxy-based DAST can do so until GitLab 18.0 in May 2025, but no further updates or bug fixes will be provided for it.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.