Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Last year we signed the Secure by Design pledge - here's our progress

Blog post from GitLab

Post Details
Company
Date Published
Author
Joseph Longo
Word Count
1,013
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

Over the past year, GitLab has made significant strides in enhancing security across its platform, aligning with CISA's Secure by Design Pledge, which emphasizes embedding security into products from the development stage. Key initiatives include increasing the adoption of multi-factor authentication (MFA) by planning a phased rollout that will require all customers to enable MFA, reducing the reliance on default passwords by using randomly generated root passwords, and improving secure coding practices through comprehensive guidelines and expanded SAST rule coverage. GitLab has also worked on increasing the installation of security patches by offering detailed upgrade plans and maintaining a strong bug bounty program. Furthermore, GitLab has enhanced transparency in vulnerability reporting by including Common Weakness Enumeration (CWE) and Common Platform Enumeration (CPE) fields in its records, and has bolstered incident response capabilities by publishing guides and open-sourcing detection frameworks. These efforts reflect GitLab's ongoing commitment to providing a secure and trusted DevSecOps platform, with plans to continue innovating in this area.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.