Securing the software factory at machine speed
Blog post from GitLab
GitLab’s CISO argues that as AI agents make software creation and vulnerability exploitation faster and cheaper, security programs must shift from measuring scans and tickets to minimizing the time from detection to verified remediation. Citing rising CVE and bug-bounty volumes at GitLab, broader vulnerability-exploitation trends, and increasing model capabilities, the text contends that traditional severity-based queues and downstream reviews cannot adequately address risks created by chained weaknesses, excessive permissions, and exposed deployment paths. It proposes a three-layer operating model: proactively discovering risks across code, infrastructure, and deployments; maintaining a foundation of unified scanning, short-lived secrets, policy enforcement, least-privileged and auditable agents, and automated remediation; and continually reassessing software after release. A central concern is the “shadow software factory,” where agents operate outside governed repositories, CI/CD systems, identity controls, and approval workflows, limiting visibility into how changes were made. GitLab presents its Duo Agent Platform and integrated development controls as a way to place agent activity, security scanning, remediation, and approvals on a common governed path, while stating that it will publish further operational guidance for organizations adopting agentic development.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 6 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.