Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Why GitLab is deprecating compliance pipelines in favor of security policies

Blog post from GitLab

Post Details
Company
Date Published
Author
Ian Khor
Word Count
1,117
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab is transitioning from compliance pipelines to a new feature called pipeline execution policies, responding to user feedback that seeks to combine flexibility and simplicity in managing security and compliance jobs. This change aims to enhance compliance enforcement and provide a foundation for future use cases. Compliance pipelines are deprecated as of version 17.3, with a migration path outlined for users to switch to the new system by version 19.0. The transition emphasizes clearer distinctions between compliance management, which focuses on visibility and audit readiness, and policy management, which enforces compliance and security across GitLab instances. Users are encouraged to migrate their existing compliance frameworks to the new policy format, which offers modes for overriding or injecting security and compliance tasks into project pipelines, thereby streamlining the enforcement process. This effort is communicated through warning banners, migration workflows, and user support channels, ensuring a smooth transition ahead of the complete removal of compliance pipelines.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.