Get to know the security and governance updates in GitLab 17, 17.1
Blog post from GitLab
GitLab 17 and 17.1 bring a suite of security and governance enhancements aimed at improving software security and compliance. Key updates include streamlined static application security testing (SAST) with a Semgrep-based analyzer that simplifies rule configuration for multiple programming languages, and the introduction of Android dependency scanning to manage vulnerabilities in mobile applications. The platform also enhances secret detection by supporting remote rulesets and introducing secret push protection, which prevents sensitive information from being committed. Container registry improvements include new features for image signing, last published date display, and container scanning linked to CycloneDX SBOM production. API security scanning sees enhancements with dynamic application security testing (DAST) and Web API fuzzing, offering better flexibility and compliance for modern security requirements. Additional features include updated vulnerability reporting, customizable merge request approval policies, and expiring access token notifications to enhance security posture in various aspects of the development lifecycle.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 4 | 616 | 101 | 53 | -49% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.