GitLab DevSecOps Report – David DeSanto, GitLab
GitLab releases their 6th annual DevSecOps survey finding that despite security being the highest-priority investment area, security is still held back by deployment demands and speed-to-market. David DeSanto, GitLab VP of Product, shares more insights from this year’s report.
Transcript
This is texturing TV. The great pleasure being joined by David DiSanto David is VP of product with gitlab. Hi David.
How are you doing? Hey, Mitch. I'm doing good.
How are you doing? Very good. Tell us briefly a little bit about yourself and what you do at gitlab?
Yeah, absolutely. So as you mentioned on VP of products, I lead our product organization that is product management product monetization and our product operations team. I join gate 11, 2019 launch our security portfolio and early this year at the pleasure of taking over all of products.
Excellent. Excellent. Well, I know we're talking security.
Of course a new a new report sixth annual. I should say new report of your devsecop survey. Yeah, definitely.
We're very excited about the results of the survey and looking forward to talking about them today. And yeah, if you've not seen the survey you can go to our website and download it. It's full of really great information thousands of people responded got some really good nuggets about devops.
It's future role of security and other great tidbits. Now I can't say this definitively but I think it's it's certainly one of the longest if this not the longest repetitive annual survey on devsecops, so it's nice to see some of that historical Trends and continuity across, you know, the adoption of Dev psychot. So well tell us a little bit.
I know you surveyed over 5,000 software professionals to do this to do this report for the this year. What were some of the highlights. What did you what are you kind of take away from maybe what what's similar and what's different?
Yeah, so I'd say the the two big takeaways I have from it one is the role of security and how it's becoming a driver of devops best practices. A lot of respondents talked about how security is driving to a devops platform and how that is causing better collaboration between all three groups that make up, you know development organizations, whether it's developers operations or security outside of that made the biggest data point was the change in the developer role at organizations over the last several years get lab as well as lots of other people in the industry have talked about shifting security left, but at the same time we're shifting developer responsibility, right developers talked about doing a lot of the traditional Ops base tasks. Now this included everything from managing their own infrastructure in training their code monitor monitoring as well as Being on call and doing things like IAC to deploy their infrastructure.
So it's been a really interesting change. The other thing that really jumped out to me is the Sprawl or the tool change brawler saying now for organizations 41% of teams, so they're using six or more tools. And that's a lot of tools to try to keep together.
And with that we're starting to see developers talk about them spending a quarter of their time, maybe half their time just managing the tasks of that infrastructure being them to being less developer and their area focus and becoming more of a jack of all trades and that's really surprising too with that that shift because now you're taking people who are really really good at writing software and expecting them to do all these other tasks that are around it. And it was one of the dilemmas balance of I've always had dilemma of are we in the tools business are we in the software writing business? Right so he can feel you're kind of taking over especially multiple teams.
Probably have six different tools, right? So you six times x sometimes. Yeah, if you think about that, right Mitch, like now, you've got not just the tools themselves, but it was referred to by responses a toll chain tax.
They're not having to not just maintain six or more tolls. They're now also having to maintain the Integrations between those tools which can be very fragile. And if you upgrade say your CI environment what if it's now not compatible with your security tools or with your SCM environment.
Obviously, you're now becoming like a troubleshooter of that environment having to engage when you upgrade and what what that impact would be maybe it's gone from breaking the build to break the tool chain because of data some integration. That's the sound. We'll all have to start saying that did you break the Builder?
Did you break the tool chain? Yeah, they used to we were talking about some of the kind of Friday Bill days. Right?
Don't break the bill. That's a while ago, but well, I'm really curious a lot of the sort of the debate or maybe dilemma about devsecopsis. What does it really mean to shift left?
What a security Engineers do how much are they involved in the the design and the architecture of software or baking security into the tool chain or what really is their role as they're shifting left? And then I'd like to talk a little bit about the developer shifting, right? So anything that you've uncovered from the survey to kind of give us some insights what people are doing.
Yeah, so what what other respondents mentioned is that continued shift left and what we mean by that is bringing the security tools into the CI pipelines so you can scan at code commit time or during a merger Quest code review experience. And what we saw is that security practitioners started talking about how they're now being shifted left with that and being able to partner alongside the development team to address security vulnerabilities early. One of the things that really jumped out at me.
Was that even though there is a common a comment about response rate of like developers and security people working better together and more collaboratively. There's still the little bit of the finger pointing where security saying well now we're shifting left. We can see 75% of vulnerabilities are introduced by developers, right and so and always say that kind of makes sense, right?
If you're writing the code you probably the person introducing it but that is definitely unintentional not intentional right? I don't think any developers wake up in the morning and say I want A zero day vulnerability in my application today but it was measuring courses. I took in computer science.
I don't recall that but I don't recall that either. Yeah, I I have to go back and think I was a long time ago, but go like hmm was there like there's like C++ 101 followed by bright vulnerabilities 102. Like I don't think that's actually how it how it works.
But you're to your point. I think what what organizations are really saying is that they want to adopt devsecops, which is a training up again and usage on describing their DeVos best practices. They're going to need to focus on how do we make it to those teams of collaborate better?
Hmm well and it's it's fortunate too because Devsecups like devops itself can really start with the cicd process that tends to be where everybody kind of was where the you know, everything comes together and certainly is a great place to start you can continue to move into IDE tools and other security elements that can happen earlier in the process. We'll talk about the shift right of developers because we hear a lot about you know, platform engineering is now a function a job title a thing, right. We also hear, you know developers don't want to do operations and don't want to do support they never did right?
So I guess the theme or originally was they'll automate it because they're developers and they're doing devops. But what is that shift right that you're seeing from the data? Yeah, so I'd say probably one of the interesting data points that came out and you just mentioned there was 47% of teams are now doing full test automation including that being leveraging mlai as part of that experience.
And that is a staggering Almost 100% increase almost double what it was last year and I think that's how developers is trying to figure out how they do ship themselves right and take on some more those responsibilities. I do think one of the driving reasons for that shift right is that teams are not releasing more often than they did before 70% of teams are releasing continuously whether that is multiple times a day one today or every few days and that's up 11% overall. And when you start to think about that the best way to do that is to get your developers more comfortable with the things that are adjacent to them to the right.
And so that is to your point understanding cities better part of Is doing, you know Cloud native type strategies and defining infrastructure and having that be part of the actual project as well as being able to understand. How do I learn more about how my app is being used and leveraging things like monitoring data feedback and ways to pull that data back over to the developer. And so I really think that that continued shift that developers are feeling is part of the reason why they see themselves wanting a more advanced programming languages and they feel confident.
They have a really strong position today on how they grow and where they can go in their career and that that numbers also up as part of the survey as well. When we have many more people entering the field right becoming developers who have boot camps left and right which are you know, all good things as well. I'm curious as the environments that we're deploying into I guess is the way I would say it it's a little more a little different than that.
But you know, we have mobile apps as well as a web apps, we're doing you know API first type designs where apis are the product we're integrating with our own systems third party SAS, you know, you name it. We're integrating with the data sources, etc. Etc.
That environment is extremely complex. And it seems to me that that's part of also that software architecture that the developer has to understand of what they're deploying into and how it's secured as well as the security people anything in the data validate that Uh, yeah, I mean there's probably a couple different data points that really jumped out to your comment about the the shift and the modern application environment. We see kubernetes continue to get more and more adoption and when you think about kubernetes you think about defining infrastructure that's kind of that natural thing that developer can begin to understand it's not in the like so I may look like I'm in my early twenties.
I'm a lot older than that and so like my career as a developer like my code is being deployed into a physical data center where I didn't know anything about the servers or the networking and all that. And now today a lot of that is a lot more transparent and I think it's what's allowing some developers to build two-way doors and how they structure their code. So that way they know of need to come back and make something more scalable.
They can do that or if they make something that is potentially like a microservice which by the way microservices also had an uptick this year in the survey. I would say A the real big Takeaway on them shifting left is the increase in that automation, you know developers want more automation. 31% of them said they're looking to add more this year because to them the biggest ball neck today is the processes around that and if they can get that automated they can move the next task pass faster get to the next project faster and continue to help the company grow.
It seems like we you know if we kind of put different lenses on the tool chain. There is the developer lens. There's also the security lands.
We do have a security tool chain. If you will that's built into that flow. Sometimes it's things outside of it too.
But I think that's really coming to the Forefront of importance of how we think about this whole process not as disciplines that happen at points in times or just collaborating. Yeah, completely agree. I think that's why you're saying developers Ops and security teams see the benefit of a devops platform, you know, and all all those cases that those percentages went up.
You know, we're seeing that mentality shift that security is everyone's responsibility. It's other responsibility of an individual and again like that. One of the things I always like to just remind people and I just like developers don't wake up in the morning and go Yes was very vulnerabilities.
Right and I do see that with that shift of them focusing more right? It's also I don't want to inadvertently break my environment. What do I do?
Right and so one of the things that we have done recently to help with that as we've actually added security training directly into gitlab at this part of our application. So if a new vulnerability shows up, The developer doesn't need to wonder what it is. They literally click and take a lesson on like what is the SQL injection how to prevent it and I think those steps is part of that loss platforms is enabling that everyone can contribute.
Everyone's responsible for the health. It's not just developers. Only write code Ops teams only do physical infrastructure data center, whatever and the security team just doesn't worry about testing apps and production and I think that that is also an interesting outcome of the surveys that Ops professionals also feel like they're wearing multiple hats now, they're needing to understand more developer practices because they're making a ship to kubernetes.
It's a 33% in the survey, right? So I'm now getting to learn how to code some of that is gonna be defined and yeah, we'll files and scripts and all the things that you know how that works from a cicd perspective. And again same thing with Security Professionals.
They're seeing themselves work side by side sometimes in the same team now what's developers to make sure everyone is more secure. Excellent. Well, I know you've been wearing your VP of product hat when during our conversation but maybe tighten that a little bit further a great thing about gitlabs is you're very transparent about you where you're going and your plans and information that you're sharing.
How does this in survey maybe even this year's survey inform where you're going from a product standpoint? What are the things that step out to you and say we may emphasize some things a little differently now or as a different mix or whatever what how's that influencing you? Yeah, that's a great point and a great question.
So the there are a couple things that come out of the survey that kind of show us that we've been heading in the right direction 61% of teams in the survey said they're now doing model Ops and for people watching this conversation between you and I model Ops is the combination of data Ops, which is your yield here ETL. So extract transform and load of disparate data sets and animal Ops or machine learning Ops, which is the productization and operable operation. I can never say that word operationalization.
So there you were like, I can handle like three Soulful words like way too big for me but of data models, right? So that is testing building deploying rolling back and we last year made a decision to begin to focus specifically on data science personas, because they benefit can benefit from devops just like developers Security Professionals operations teams, and so forth and seeing that That's a trend. That's just jumping in that survey.
It's a really good sign that we had in the right direction a couple of other ones for you and see you asked me to put the VP hat on all the two types. Now, you can see how excited about get lab and what we're doing but one of the things that we touched on a little bit ago is we want to focus on more automation. And that's because again 47% nearly double last year teams are saying they need automation is to stay competitive and moving forward in what they're doing.
And so one of the things we've been doing is adding machine learning to gitlab. So not only we doing that first part where we can build and train but we're using it to make it lab smarter. And so last year we acquired a company named We acquires my name obstrate last year too, but we acquired unreview who focuses on bringing machine learning into the code review experience and that ship is a beta a little bit ago and GA here shortly.
It's a very excited about that as well. And I say the last thing that really jumped out is the importance of code review and being able to release code and so when looking at Work from a gay lab perspective everyone comes together in the merge request that is your developer for code review their manager QA team security teams office teams all come together that one spot. And so we really want to focus on making that a lot easier because that toll chain count is so high.
We want to be able to help people be more engaged and having what they're doing. And so if you're looking at this as a whole. For us it's about improving usability and giving people whether it's an open source project or an Enterprise the ability to do what they need to do successfully and be able to work collaboratively because the last thing for you is that people releasing software a lot faster, right?
And so the only way to do that is to automate leverage machine learning and make it easier for everyone to collaborate together. I think a symbiotic relationship there right Automation and moving faster yet and to be too simple about it. But well, it's fantastic appreciate you sharing that perspective too and appreciate the openness transparency that get lab has the approach that you take.
com as a particular link. com. You'll see a link for the survey.
You can fill that out. You'll get it be able to download it look at it. It's all worth it.
And to your last question for those we're not familiar how transparent we are. Our entire strategy is live on our website. So if you just go to the same website, you do slash Direction, you'll see where we're heading over the next several years and they'll Julian individual components of the product see what teams are working on it and of course our issue trackers live.
So if you want to go in and comment on issues comment on epics ask questions thumb things up. You're more than able to do that. I highly encourage that our product team loves talking to users whether you are an open source Community contributor or whether you're one of our Enterprise customers.
And so that's one thing I love about get Labs. We're very collaborative. We're very transparent and it allows have an amazing user base who love the product.
Very true. It is one of the fascinating and I think very positive things about get lab amongst others. So thank you very much David.
Appreciate you joining us, and hope folks will download this survey. It is enlightening. I'm interested to hear in some of the the big jumps in the data, too.
So take care. We'll look forward to seeing you again David. Thank you very much.
Have a good day. You bet.