GitLab Runner update required to use SAST in Auto DevOps
Blog post from GitLab
GitLab is implementing a significant update to the Static Application Security Testing (SAST) job definition with the release of GitLab 11.6 on December 22, which may cause SAST jobs to fail if they are run by a GitLab Runner version older than 11.5. Although these failures will not block pipelines, SAST results will no longer appear in merge requests or at the pipeline level, impacting users utilizing Auto DevOps with outdated runners who value security reports. This update, which employs a new reports syntax essential for displaying SAST results in the Group Security Dashboard, is not compatible with GitLab Runner versions prior to 11.5. To mitigate the issue, affected users are advised to upgrade their GitLab Runners to at least version 11.5 to restore functionality, while those using shared runners on GitLab.com or newer versions are not affected. The change is set to be part of GitLab 11.6's release and may be included in an early release candidate version, affecting self-managed instances upon upgrading to the new version or users on GitLab.com when the RC version is deployed.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.