2023 Global DevSecOps Report – David DeSanto, GitLab
According to GitLab’s 2023 Global DevSecOps Report: Productivity & Efficiency Within Reach, the top two benefits respondents have seen from adopting DevOps and DevSecOps methodologies were improved operational efficiency and developer productivity. GitLab Chief Product Officer David DeSanto speaks to the importance of developer satisfaction and productivity as well as workflow and efficiency – especially in the face of rapid AI changes.
Transcript
This is Textron tv. Hey everyone. Welcome back to Textron tv.
You know, I have one of my favorite people here to talk to. He, we usually see each other in person at events, but we haven't been to, well, r s A was the last time I saw him, but that was already a couple months ago, so I'm happy to have on Techstrong with us today. David DeSanto.
David, if you don't know, is the chief product officer at GitLab and a frequent techstrong guest. David, it's great to see you. How are you?
I'm doing great. Great. Uh, to be back on and, and see you, you're looking, you know, very healthy and ready to tackle the DevSecOps, observative other, Well, I lost some weight, so it does make you look healthier, but, you know, one day at a time, man.
Hey, David. Um, look, I, I think our audience really knows GitLab and, and I think they know you, but as I mentioned, you are chief Product Officer there. Why don't we talk a little bit about, you know, GitLab, there's a lot of product at GitLab, right?
Why don't, there is, we talk kind of your role there and, and then for those who, you know, for the stragglers out there who maybe don't know GitLab, maybe a quick background. Yeah, absolutely. So, a, as Alan Chair, David DeSanto, chief Product Officer for GitLab, I've actually been at GitLab almost four years now, which is time flying by.
I focus on making sure we have the right product strategy and that we're delivering against our, our long-term vision. And so GitLab provides a DevSecOps platform, and we refer to it now as being an AI powered DevSecOps platform with the introduction of AI last year into the platform. And we focus on helping companies deliver software faster, more efficiently, while also being secure.
And so that allows GitLab to provide everything from our planning functionality to S cm CI i c d security, both scanning, uh, at the time of commit, as well as scanning applications in production and of course monitoring and analytics to make sure applications are working as you expect. The one thing I'd like to tell everyone is that GI GitLab is an enterprise DevSecOps platform, and it's trusted by more than 50% of the Fortune 100. Absolutely.
Um, and, and it's been an amazing ride. You know, I, I, so David, my involvement with GitLab goes beyond four years. I think it goes, I think almost since the company was founded or came outta yc.
And, and, um, it's been a, a joy to watch the growth of this thing. I've had many friends still, so I'm still at GitLab, some former Labber. Um, and it, you know, it's one of the great success stories in DevOps, of course, over the last, I'm gonna say the last year to two years, David, we've really seen GitLab not pivot, but put a real enhanced focus on, as I, as we had it at R S A this year, DevOps is now DevSecOps.
Right. And, and you know, that's correct. GitLab was one of the first DevOps companies to really zero in on DevSecOps with some early acquisitions around, you know, DevSecOps technology and, and, and shift left technology.
And, and even more than that, as I said in the last year and a half, two years, really kind of focused, uh, GitLab on, on a DevSecOps mission. And it's proven, I, I think Precent or, or at least right, right. Security is a, yeah.
Is a top priority here for everyone. Yeah, Go ahead. Oh, yeah.
I was just gonna say, you're, you're right, Alan. I actually, when I joined GitLab in 2019, we were less than 800 employees. We're an now over 2000.
I joined GitLab to help shift security left. The first time we actually spoke was at an RSA in 2020 where I remember your opening question was, David GitLab DevOps, why are you at a security conference? And so we began shifting security left, truly shifting Git left, getting Delta Code commits helping developers fix vulnerabilities before code is committed.
And it's allowed GitLab to go from being known as a an s CM company to being known as a security company. And I think it's really cool to see that you're right. I'd say about two years ago, it really started to catch on for everyone.
And now all of our conversations with our customers revolve around security, compliance and software supply chain security. Yep. Excellent.
All right. The topic of our discussion today, Dave, is, uh, we have GitLab's 2023 Global DevSecOps Report, uh, productivity and efficiency within Reach. We hope so, right from your mouth, David, give us, give us some highlights here maybe.
Yeah, so this is the second installment of the report this year. So if you are watching this, you haven't seen the first instance of the report, I highly recommend you look at that as well. Uh, there's also a really great interview.
I can't remember if it was Alan and I or maybe Mike Bazaar and I, but we talked about that report as well. It's also very exciting. But this one was focused on productivity and efficiency, and I think one of the, uh, surprising results coming out of it is that we're seeing developed productivity be the number one factor driving DevOps and driving scale for organizations.
And we've always known that developer productivity is one of the benefits of DevOps, but it's actually very encouraging to see that developer influence and developers being able to help companies scale better and become more effective at delivering software and of course, adopting DevSecOps best practices. And so that really jumped out to me as I've read through the report, uh, that, that it's good they have their voice and, and they're causing influence. I think that's great.
Absolutely. A absolutely. Um, you know, look, I always like to ask people what are the big three takeaways for this?
Yes. Yeah. So obviously with the report being focused on productivity and efficiency, you can see those are top of mind.
I think the things that are interesting is that organizations who are using their tools strategically ship software faster. And so that's the big number one takeaway. This included good use of ci, cd, DevSecOps, platforms, AI and ml, which probably comes as no surprise with AI becoming the thing that everyone talks about.
I made, actually, as a side note, now, I made a joke. You can't spell David without ai. And so That's, that, that is true.
Yeah. It, it, it allows me to talk about AI a little bit more than, than normal. Uh, okay.
7 times. That is, again, I should clarify that, that's with developers who can onboard within four weeks. So leveraging a DevSecOps platform reduces that time to the first code commit, which I thought was really exciting.
The, so let, let me, let me ask a question. Are you talking about onboarding a developer from a personnel point of view, or Yes. Yeah.
It's about onboarding a developer onto a new project. So they could be new to the company or they, they've switched teams and respondents who use DevSecOps platforms. Were almost two times more effective at onboarding developers within four weeks.
And I can tell you one of the success stories, as I never forget lab, is that every time I talk to customers, uh, for those who haven't watched you, and I talk for the last several years together, um, I've been in Europe meeting with customers all through the United States. And what we always hear is that Glab accelerates onboarding for customers. And we've heard organizations say they've gone from weeks to days.
And I think that resonates in the second data point from the report, is that if you are using DevSecOps platform, you're two times, almost two times more likely to onboard developers faster, which is really good. I, when you think about developer productivity and developer engagement, the faster they can get contributing, the better they feel about the project. And I think that really falls into my third item that really resonated with me as a takeaway was that retaining and hiring, uh, talent is still a challenge for companies.
You know, we saw that get better a couple years ago with the pandemic, with the people working remote companies, having to streamline how they deliver software retaining talent is very important. And so what they found, what we found is that, uh, still almost 50% of organizations say it's hard to acquire and maintain that talent. And so if you are using a DevSecOps platform, you're gonna have better developer productivity and engagement.
And if you're using your tools, well, you deliver software faster. And so I, that's why I see those all three tie together, and I think they're really great takeaways. So I'll tell you, the report is long and it's got a lot of other really great nuggets in it as well.
Absolutely. Um, so David, let me, you and I, as you mentioned, we talk a lot. Yeah.
You know, an interesting sort of anti-pattern, let's call it, that I've been seeing in the DevSecOps space is for so long in DevSecOps, we talked about shifting left, shifting left, shifting left, letting the developer have more input, have more control, be more responsible regarding security, let's develop security tools that are developer friendly, right? Mm-hmm. I think we've seen sort of a, a pushback.
So we get things like platform engineering that say, Hey, let's, we're gonna set up the guard rails, the environment that the developer works in. So they don't, they could do what developers want to do most code. Mm-hmm.
Right? The SRE will take care of this. We're gonna do, you know, supply chain security, almost like an anti push shift left where we're gonna, yes, the, the developer does care about security, but they're not a security pro and let's stop making it such a, a high priority for them.
And that to me is, I feel like we're doing the DevSecOps Chacha two steps forward, one step back, right? Yeah. What do you think about that?
Yeah, so I, what I'm saying, and again, it it's talking to customers that includes end user Organizations, right? Who's talking to more people than you? Yeah.
That's actually funny you say that. Uh, I think myself and our cmo Ashley are racing around the world to see you can meet with the most amount of people I'm currently winning. So at the time of us talking, I'm number one, Ashley, you gotta try harder.
And so the, uh, the thing that I'm saying is that, you know, when DevOps started becoming a thing, it was about efficiency for that team. And so we saw a lot of developers who were taking the time to build their, uh, c I c CCP pipelines, select all the tools and organizations, ended up with all of these disparate tool chains for each team. And people said, well, look, we're efficient.
Look what it's doing. Everyone's picked the right tools for them. And what organizations have found is that when someone leaves, who's responsible for that, you all of a sudden have no knowledge about that, that environment or, you know, you end up with very fragile tool chains cuz they selected tools that don't really work well together.
And so IC platform engineering as a response to that to say DevSecOps is really important to the organization, and the only way we can continue to be efficient is if we standardize on this specific tool chain and a platform. So that way everyone's getting the same benefit. And instead of developers having to learn how to set up Jenkins or set up GitLab CI or set up Datadog for monitoring or set up Jira for issue planning, they can have a single team who's responsible for that environment and set it up.
And so I've not seen platform engineering as orthogonal to DevSecOps. I actually was reading an article about a month or two ago about how they were comparing them and saying, DevSecOps is dying and it's now platform engineering. And I think that's kind of missing the point I see platform engineering is that standardizing a DevSecOps platform for the organization.
I, I don't disagree at all. You know, we, we recently, uh, partnered with the folks who put on, I think it was platform com or something like that. It was the platform engineering virtual conference.
I mean, had a great turnout and I had a chance to really talk to a bunch of people. com and Security Boulevard. And I, and I think that is the problem.
And, and this is quite frankly, it's an ongoing problem in tech. We tend to think as the new thing replacing the old thing. But, you know, old tech never dies and, and what, and what we do, and I learned, my friend Brad felt, who pretty well known dc he always used to tell me, you know, 98% of tech innovation is evolutionary, maybe 1% is revolutionary.
And, and by evolutionary it builds on what, you know, we build, we keep building on what came before it. So when we look at things like platform engineering or SRE for that matter, or some of the other things, or even DevSecOps itself, DevSecOps is built on top of DevOps. Mm-hmm.
Right? Which itself is built on top of Agile and lean. And so, you know what I mean?
It, it's, I do We these things, not one doesn't replace the other. Yeah. I, uh, I always feel like in, in tech, we always have to kill something for something else to be born.
And I feel like that's not the case in a lot of, in a lot of areas. And I think maybe it's one of those where, uh, we all have to do a better job explaining and understanding what the tech is doing. Because I do agree with you.
I, I see your SRE team is supporting a platform engineering approach, which is standardized on the DevSecOps platform, which is allowing everyone to do agile enterprise, agile planning, the I CD best practices and so forth. I don't see them as orthogonal to each other. And if, if we thought about it that way, I think you would not give organizations the credit they deserve for being able to, to make digital transformations and get to the point where they, they are where they can have a developer as, as they should in the survey, right.
Onboard in, in less than four weeks. And in some case, say you're using GitLab remote development and are AI assisted features maybe onboard in minutes or hours onto a project. And that's the value of platform engineering as part of your DevSecOps practice.
Agreed. Very cool. Um, we're almost outta time, David, beyond, beyond this GitLab 2023 Global DevSecOps report.
Other exciting GitLab, uh, and, uh, goings on that you wanna share with the audience? Yeah, I'd say the big thing that I'm very excited about is we launched GitLab Duo a couple of weeks ago. GitLab Duo is our AI assisted DevSecOps workflows that are built into our DevSecOps platform.
And we took an approach where we wanted to be enterprise grade, which means we're privacy first. Your code stays your code. We don't use it for training or fine tuning of our models, as well as being very transparent, which GitLab is well known for, and GitLab's the most transparent company, and I should say publicly traded company in the world.
And so we're documenting how we train the models, what models we're using, and all the information goes with it. So as an enterprise, you can feel confident using GitLab and AI together. But the last thing with it is that we've also focused on making everyone more efficient.
And so when we're talking about the DevSecOps survey or we're talking about platform engineering and all the teams that go into building software, you need to help everyone be more efficient. Even if you made your developers a hundred times more efficient, you're gonna break something else in your supply chain or in your value stream depending how terminology you want to use. And so we've added AI to our planning functionality, our c I D functionality, we're helping security teams be more effective in reviewing and triaging and resolving vulnerabilities.
And so today we have about 10 features that have shipped for, uh, AI powered components within GitLab. And I'm very excited to see the effort the team has done this year to really show that you can make yourself more efficient if everyone can contribute more effectively. Absolutely.
Hey man, David, actually we should also mention, uh, GitLab's gonna be over, uh, at Black Hat, which we'll be doing some live videos from Black Hat. Hopefully we'll be able to have. I I know you aren't personally not gonna be a GitLab, uh, black hat at this point.
Yeah. But, uh, that's correct. We have some GitLab folks there and, uh, if you're going to Black Hat check out GitLab, they, they are exhibiting there.
David, as always, a pleasure to have you on. Keep up the great work, give our regards to all of our, our GitLab, and uh, we'll be in touch soon, man. Yeah, thanks for having me again.
And likewise, let everyone know I say hi there. All right, David DeSanto, chief Product Officer for GitLab here on Textron tv. Go check out that GitLab 2023 Global DevSecOps report.
If you look at the top right of your screen while you're watching this, you'll see a link and that link will take you to a download of the report. Um, so new innovation here at techstrong tv. So it's clickable links, and you can download this great GitLab report right from your video or well by clicking on the video, hopefully on your phone or browser or however you're watching this.
We'll be back in just a minute with more text on tv.