How we're using DAST 2 for easier scan configuration and reduced noise
Blog post from GitLab
GitLab's blog post discusses the implementation and benefits of using Dynamic Application Security Testing (DAST) tools to identify security vulnerabilities early in the development process. Initially, GitLab utilized DAST version 1, optimizing scan times by splitting the scans into parallel jobs and excluding irrelevant rules to prevent CI job timeouts. With the release of DAST 2, GitLab upgraded their CI jobs to leverage new features such as vulnerability aggregation, which simplifies vulnerability management by grouping duplicate findings, and improved configuration options for browser-based scans. The upgrade process involved adopting the DAST_ONLY_INCLUDE_RULES CI/CD variable, enabling auto-updates, and removing deprecated configurations, which reduced complexity and enhanced efficiency. GitLab continues to explore new DAST features, aiming to improve user experience and security.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.