Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

How we're using DAST 2 for easier scan configuration and reduced noise

Blog post from GitLab

Post Details
Company
Date Published
Author
Nikhil George
Word Count
1,352
Company Posts That Month
21
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab's blog post discusses the implementation and benefits of using Dynamic Application Security Testing (DAST) tools to identify security vulnerabilities early in the development process. Initially, GitLab utilized DAST version 1, optimizing scan times by splitting the scans into parallel jobs and excluding irrelevant rules to prevent CI job timeouts. With the release of DAST 2, GitLab upgraded their CI jobs to leverage new features such as vulnerability aggregation, which simplifies vulnerability management by grouping duplicate findings, and improved configuration options for browser-based scans. The upgrade process involved adopting the DAST_ONLY_INCLUDE_RULES CI/CD variable, enabling auto-updates, and removing deprecated configurations, which reduced complexity and enhanced efficiency. GitLab continues to explore new DAST features, aiming to improve user experience and security.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.