Cindy Blake- Track Intro
Intro to DevSecOps. Has your application security been able to keep up with your DevOps velocity? Is security an enabler or a blocker? In this track we share best practices and lessons learned with your peers. Learn about how teams are reducing risk, shifting left, and addressing security and compliance challenges with GitLab.
Transcript
So. We're so excited you're here. Security belongs in dev ops, whether you believe it fits squarely in the middle as dev secops or you believe it's ubiquitous and woven throughout your devops methodology.
Either way, security is an integral part of creating software. As the new study showed many, many years ago, it's far cheaper to find and fix security vulnerabilities in DEV, but that's often easier said than done. Embedding it within your workflow has been a challenge for many.
Traditional application security tools are not built for rapid iteration and empowering the developer with lab. We do empower the developer to find and fix security flaws within their native workflow, while at the same time offering security pros visibility into application risk much earlier. By using Galab, you can automatically scan all of your code as it's changed and remaining and manage remaining vulnerabilities more efficiently as your organization cranks up the velocity of its software factory throughput.
I'm excited to share that we have a robust lineup for you today. First of all, Amy Martien with Forrester is going to share her view on the state of D evSecOps. The market's evolving and you won't want to miss her thoughts on this.
Joe Lusk with Mabel, one of our partners will share how they views get them to shift left on their quality testing using GitLab CI review app for testing a running app earlier in development. I. pipeline.
So we've made it easier for our partners to integrate with GitLab.. James Francis and Resarch will share with you how check marks and white sauce, respectively, have integrated their scanners into the GitLab's request for the developer. Why?
Sources also make it easy for the security team to scan results across projects by using Galab Ultimate in the security dashboard. Now, if you have your favorite scanner and you'd like to see them integrate with GitLab, check out our partner integration page, it has detailed instructions on how to integrate for the best customer experience. Now, I'm sure you expect some cool new stuff from GitLab commit, right?
We don't want to disappoint, so David DeSanto and Sam Curre will share how we are integrating our most recent technology acquisitions, Peach Tech and Fuzzy, to bring first testing capabilities to the mainstream by automating and embedding testing within the CIA workflow right alongside our other scanners like SAS, Das Container and dependancy scanning, developers will be able to find security flaws and logic flaws and more beyond those vulnerabilities that are known. Now, this addresses the case of you don't know what you don't know to test for. This could be a game changer for application security testing and will certainly be useful for testing APIs.
Even better, the integration has already been done for the first few languages. So check out our release post and learn more. Next after that, you GitLab.
We want to help you not only shift left to find and fix vulnerabilities earlier, but we want you to help developers learn secure coding to your developers if ever know about the actual exploits against applications they developed. Probably not, unless it was egregious. Our newest lab stage called Defend will help you monitor your cloud applications after deployment and not only provide insight back to the developer, but also provide the ability to block an attack.
Felipe and Wayne, together with a customer, Nico Mesan, will show how our development platform can get everyone on the same page while better managing risks brought from new attack surfaces like Kubernetes. Last on the agenda, I'm going to show you how you can contribute to GitLab find items on a road map that are most relevant to your interests and more. Our tagline is everyone can contribute.
But do you know how I'll show you now. Our speakers will be in the chat during their sessions and will likely be around for continued Q&A for much of the day. I'll also be there throughout much of the day and chat and please engage with us there.
com or at cblake2000 on LinkedIn. Now, in addition to our sessions, be sure to check the schedule for the networking times. Also, let's engage and keep this as real as we can when we're all stuck at home.
We're so glad you're here. Thank you for coming. You belong here.