Cindy Blake – Contributing to the Secure & Defend roadmaps
Cindy Blake invites you to contribute to DevSecOps
Transcript
Hello, I hope you've enjoyed the sessions so far. We have a lot to be excited about when it comes to GitLab security capabilities. I'd like to take a few minutes to show you where to find information about our roadmaps and how to contribute to ensure our solution meets your needs.
While these examples I'm going to show you are security focused, the methods of how to find things will apply across lab velocity is a key driver to develop environments, but trajectory is equally important. A good lab. We believe iteration is a key to growth.
In fact, it's one of our core values. Because of this, we iterate very quickly on a roadmap. We start with a minimally viable product and go from there.
And we love input your input along the way. So let me show you how you can contribute. But first, a little context that I think would be helpful.
I've been with Jet Lab just over two years and in that time we've gone from minimal viable scanning capabilities to a full fledged application security solution. We started with SAS and we've built on that DAST container scanning, dependancy, scanning license, compliance, sequence detection and on and on. And in fact, in addition to the scanners, we've added a security dashboard, vulnerability management, Container Network security and more.
So you can see that our growth isn't limited to security. And what's not on here is a security API that's enabled other scanning vendors to integrate their results in the GitLab. And we've built out our alliances program to make it easier to integrate with GitLab.
So now you can use your favorite scanner and pull those results right into Galab Ultimate for the pipeline for the developer and the security dashboards for the security team. Checkmarks and my source are both doing presentations as part of it. I would encourage you to check them out.
Now, in order to take a more focused view on security and on dev ops, it helps to understand our nomenclature just a little bit. First, if you're not familiar with Gitlow, we are a complete dev ops platform delivered as a single application. I and we call that stage secure.
Now, at the same time, we want to provide closed loop feedback like that, which Amy talked about in her session to the developer about potential exploits in their applications in production. We call that stage defend and that monitors app environments for threats. The flagship capability there is Container Network security, but there's a lot more coming and it helps to know these stage names secure and defend when you're navigating our directions, pages and our roadmap pages.
So let me go on to the roadmap and I'm going to give you a little bit of caution. First, please don't take these things with a grain of salt. What I'm showing you is a snapshot in time.
Our road map is not a marketing thing. It's actually auto populated from the issues that our engineers are working on. So it changes real time, just as you would expect.
Development changes real time. So see the Web pages for the latest information. Now to know where you're going, it's helpful to know where you are and where you've been.
So let's talk about the releases for a moment before we get to what's coming. com, which is our source offering releases continuously while the self hosted are on premise, GitLab releases on the twenty second of every month to find our monthly release highlights, simply go to the blog. And here's an example of a release posted on the blog from this was from July 22.
And you can see the highlights. And as you go down the page, you'll see all of the details of everything that came out in that release. com and what's coming to us to the self hosted, you can check out this preview page, which again shows highlights of big things, as well as all of the features that are coming.
And if you prefer kind of a list view, that may be much, much longer list of what's coming. Check out our upcoming releases page. And here, this is organized by release.
So right now, I'm looking at what's coming. This is being recorded in advance. So it's not quite is before August 22nd and it's organized by stage.
So that's why it's important to note to understand that we have a secure stage and a defense stage. So here is the secure stage, all of the issues that are being worked on and you can drill down and see those and actually look at what our engineers are looking at. It's also helpful to know not only the individual issues that are being worked, but the overall direction.
So, again, if you want to look at what's coming. And the overall direction. You can look at the this directions page, there's a directions page for every stage.
You can also find the upcoming releases here. That's what I was on. But this tells you the three year view, the one year view, who we're targeting.
And it even talks about what's not being worked on and why there's a page like this for Secure and a page like that for defense. Now I'm going to show you also, if you want to really focus on dev cops, there is a dev stuck up solutions page. And on this page, it's got all kinds of information and videos about the how to use GitLab for to shift left.
But it also has this coming soon section. Now, this is not as complete as the one if you're looking at the long list of upcoming releases, but for secure. But what this is, is honestly my favorites.
This is I'm highlighting my favorites here. But let me use one of these as an example, we've got some exciting stuff coming up around vulnerability management, around Fuzz testing with our most recent acquisitions there and container security. But I'm going to take one of these as an example and I'm going to show you what you see.
So and this is from the if you looked at the upcoming releases and clicked on one of those items, you'd see this as well. So this is the actual issue that the developers are using to understand the proposal. You can follow along and see who's assigned what they're working on.
The really cool thing is when it's a UI component, a user interface component, you can see the mockup here. So this one's pretty exciting right now on the dashboard, you can filter by type of scan. So DAST/ SAST dependancy, scanning and so forth.
We're adding an element may not look exactly like this is is a mockup in work, in progress, but we're adding an element to show so you can filter by the actual vendor. So maybe I only want to see white sauce or I only want to see GitLab. So this is really cool and this is coming.
You can see here you can upvote items and that is a key driver for. Prioritizing are our changes and our roadmap, let's say, though, that this wasn't exactly what you had in mind, you've got an idea for something different. Well, see this new issue button, you can create a new issue yourself.
So not only can you comment on what's already there, but you can open an issue yourself. And this will gives you some advice on your on what to fill out. So this template here is I've got a proposal for a new feature, and this gives you advice on on what to do and to to pick that.
I've picked a template and I've picked a feature proposal. So simply submit that goes straight to the engineers and the product managers for consideration and. Helps you contribute, so I hope this was helpful for you.
We really mean it that everyone can contribute, so please do and enjoy the rest of commit.