Reduce supply chain risk with SBOM-based dependency scanning
Blog post from GitLab
GitLab 19.0 introduces SBOM-based dependency scanning to enhance application security by identifying vulnerabilities in third-party code dependencies, addressing the challenges posed by deep dependency trees and fast release cycles. This feature creates a software bill of materials (SBOM) that inventories every direct and transitive dependency in a project, allowing developers to trace vulnerable packages back to their source and focus on those actually used by their code. The SBOM-based analyzer, supporting over 24 package ecosystems, offers a more comprehensive approach than traditional scanners by parsing lockfiles and dependency graphs directly. The tool allows continuous scanning for new vulnerabilities and integrates seamlessly with GitLab's existing CI/CD workflows, presenting findings within merge requests and on vulnerability dashboards. GitLab 19.0 also introduces security configuration profiles that enable teams to enforce scanning standards across multiple projects easily. This feature is available for GitLab Ultimate customers and is designed to streamline the transition from Gemnasium-based analyzers, providing thorough documentation and support for a smooth migration.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 2,324 | 403 | 114 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.