David DeSanto, GitLab | KubeCon + CloudNativeCon NA 2022
David DeSanto, VP of product at GitLab, joins Alan Shimel at KubeCon to discuss how GitLab provides an end-to-end software development experience. David also speaks about GitLab’s newest software supply chain security initiative, which focuses on proactive security remediations and regulatory compliance functionality.
Transcript
This is texturing TV. Hey everyone. We're back here live in cubecon, Detroit.
Cloud-nativecon. Thanks for joining us on our first day of coverage here. From we're actually on the show floor.
I don't know how much of the background noise you guys pick up because the mics are pretty good. Thank God, but it's a pretty loud show floor. It is busy.
Yeah, it's busy. It's nice. It's good to see busy, but the boots are pretty spread out.
So it doesn't look as crowded as I think it really is right. So let's dance. Anyway, I want to introduce you or reintroduce you to David DeSanto Dave's been on our show a few times.
From gitlab actually, we would just talking the last time I think I saw David in person. Was it RSA conference? Two years ago right before right before the covid.
Craze the craziness started David. I got everything right so far you did. Yes.
All right. We're headed the game. So David I mentioned you're from get lap, correct and our audience.
Needs no introduction to get lab. Obviously, we covered a bunch and it's a huge player in this whole Echo System. It's devops can't date of but let's talk a little bit about your role and get lab.
How's that? Absolutely. So I lead the product division at lab that includes product management our monetization operations and ux or user experience.
excellent and You know what? Maybe there are some people but we should do a level set. Yeah before we don't know what's new we get left.
Get left. Yeah, so get lab is the one devops platform. We focus on providing the entire end-to-end software development experience everything from planning.
So doing issues epics tasks playing out what you're going to build the actual coding you can use our web ID other web ideas as well through code review merge request experience out to CIA CD monitoring applications in production and security and specifically with kubecon. We're talking a lot about our Advanced security and compliance functionality. It's building to our platform.
Very cool great. So we're here at kubecon. You guys announced some I think it's pretty big news, but we'll let them judge.
Right? What what's the news? Yeah, so we've decided as a devops platform and I'll say a Dev secops platform that security and compliance needs to be at the Forefront of how you build software and whether that has been the recent software supply chain attacks, whether it's just giving you visibility into what's actually going into your software is very important to us.
So what we were announcing this week is a focus on software supply chain security proactive security remediation and a focus on Regulatory Compliance functionality as well. What I'd say, the things that are probably the great highlights that people will really connect to on the soft first place in security front. We're really focused on providing things like SLSA to adaptations.
So, you know, what's going into your software having better visibility into compliance violations and Where your packages are coming from on the product of security the thing that everyone's love so far in the booth interactive security training. So yeah, so as a developer if you have committed code to get lab and security is getting runs. We find a vulnerability you can get bite-sized instructions video training on how to like, well first why that's vulnerability and how to remediate it.
So let's let's talk about this. Yeah, absolutely. So based upon that I I would guess that it's The video corresponds to a given vulnerability cve or something, correct?
Yeah. So just imagine we'll say Alan you've written some code. You've pushed it into your project with gitlab and security scanning is built in it automatically kicks off it comes back and says you On your new code online 10.
There's a sequel injection. Let's see. You don't know what a SQL injection is they're still developers today who don't always know what's security vulnerabilities are right.
They know it's bad. They just don't know what cause and how to fix it. Right?
And so instead of you just reading the gitlab documentation, which has been there for a while right you now have the option to click on a video link and I'll take you to a short video that introduces the vulnerability. How it happens and how to remediate it. And then you as a developer are now an even better developer, right?
Yeah. I know and you've now learned and and the key is that the bite size are very short. Right?
No one has time to sit through it three hours training video, right? But if in five minutes we can show you the do's and dots of how to not do that again. It makes you just a better developer right?
Great. Why did anyone think that yeah. Good idea, actually.
you know overall I think this is a theme we're seeing now, which is security is Keep in mind I've been in the security world for 25 years. I've been hearing what a priority security is for 25-30 years. Yeah, but it's really real now.
It truly is Right gitlab others who even here on the, you know at UConn. Security is becoming like almost job one. Yeah, I I would say so I've been doing security almost as long as you have viewers probably think we're in our 20s, but maybe not good for a very well.
You look younger but go ahead a very kind of you. but like there was a point in earlier in my career where security was the thing that these Specialists do right and They and they still exist today, right? We know lots of them.
I'm sure you do I do right? But as companies have evolved Securities had to evolve and really when you look at what we've announced this week at kubecon. It's about how Securities everyone's responsibility right?
The thing that we just recently completed was our annual DevSecOps survey. And that was a parent in the results. We had over 5,000 people respond to the survey and answer questions and everyone whether it was like Dev people security people obvious people they all felt security was their responsibility and the best way to do that is to give them the the power to be able to be informed understand it and be able to action the first time as you said I met you we were talking about how gate level was getting into the security space and today get Labs now recognizes security provider, which is a phenomenal accomplishment.
No, no, absolutely, right and so now it's trying to devops. Yeah, absolutely you train. Here's let me play Devil's Advocate.
Absolutely, please do. some of this some people I've spoken to have said, you know, it's really unfair. That we're putting all of this security onus all of the security responsibility on overworked Developers.
They've got so much on their plate right? We're making them do testing. We're making them do security testing.
Now. We want them to learn what vulnerabilities are and what it means. How much can one person be responsible for right?
Yeah. So ahead. I'll take your comment a step further good.
I the one thing that came out on our survey is that developers feel this onus now to maintain the devops tool chain. And that the respondents 25 to 50% of their time. They said they spend on just that so not coding.
They go to school. Learn how to write software right software. Well, right build very complex very scalable AppSec.
But then their job is maintaining their their devops pipeline, right? So I think the thing that makes people live very unique and I I say this is both the person who leads our product organization, right? But also as someone who's very passionate about devops and I'll say deaf secops, right?
You've got to make security approachable and then you you like the training that that's the solution to this like if you were to say to a developer, I need to go run this security tool. Interpret the results and make the right decision. Your developers are gonna be very unhappy right and they're gonna want to find a different job.
But if you bring it to them in a way that they can understand it and they can learn from it. 206 is yeah or education and to make it even worse right? Like security.
I love security right? I hope that comes through to everyone like it's a passionate I get it but like you've got CVS you have the miter attack framework give the nest cyber security Frameworks the last top 10 and stop 20. Yeah, so and it goes on and on developers are not gonna be able to understand all that nor should they but if you give them the what is the sequel injection developer terms and it way to understand it.
They'll write better code and they'll be happier. Well, so that's the key too. I you haven't said it but you hint on it, which is I'm not looking to make a developer security pro security.
Admin. I'm looking to make the developer a better developer. Right right and by him learning what a a sequel injection or how a buffer overflow works.
So whatever it is. Makes him a better developer not a developer. Slash security admin, right?
No it and that's that's important it is and that gets into the the tool the tool chain sprawl that right. Yeah, you're making developers now need to be it Ops people and understand it and that and that's literally not how you solve the problem. Right?
If you can get all primary groups whether that is developers security team members Ops team members. I'll go further and say get your product managers your QA teams. All involved and doing their job the best everyone's happy.
Everyone wins right agreed. Right? And I think it's really become key because you know three five years ago.
You know, it was like the I've got a developer. Does this I got a security team does this but to deliver software at the rate companies need to deliver software today coupon people talk about delivering code multiple times a day. You can't have your developer be a security expert in an option, right?
it's just say that you can't there's just so many straws you can put on that camel's back. Yeah, but this great how do people I mean this is built into the court get up get lab. Absolutely.
Yeah. Yeah. So the big thing that makes get lab unique is we're a devops platform.
That means that we're delivering all that value in a single product. It's got one UI a unified data model and it gives you all the benefits that you would get from scmci and security but now we're announcing how governance and compliance fits into that as well. And that as well.
Yeah, and if you think about the updated the 20 second of every month, yeah, so I'll say it's been a hundred and thirty three straight months. It's quite an accomplishment. Yeah, it is man.
Yes it is. Yeah good for you guys. Yeah, absolutely.
And like for those who are here, please check out the booze. We're doing demos of the new things we announced as well as showing where we're going as a company. I think that when you look at how you deliver software's safely securely and you want to do a quickly having that one place where your entire team can come together means everyone's doing their best.
They're collaborating their transparent, right? Excellent, man. Yeah, and if you're not here and you want to check it out online, yeah, please go to our website.
com. I will also say if you just want to get a census to what get lab is doing and how we operate as a company. You can go to gitlab unfiltered on YouTube We post the jewelry of our company meetings there our brainstorming interactions with the community book it is we're one of the most transparent companies I've ever worked for and Oh, no, you're the most transparent company you ever worked Franklin Gary you can you can say that I yeah, but I are gonna go with the most right but what I will say is that we love talking to users.
So go to the website you like what we're doing and you want to engage my team. We've got 50 plus product managers. They want to hear from you.
Right? So go to get our driver you can go in and comment on issues and epics. Absolutely so actually hey man, it's a pleasure seeing you in person.
Absolutely RSA April this year if you coming and we are here cops thing on. I think it's I forgot the date. I think it's the 24th of April.
I think it's yeah, not Monday is our devset gospend. It's in my scony. Whats County?
Well, no our boots must I would def sync Ops we put on a whole day. All right. It's in my skoning South this year.
Okay, awesome. And it is it's that Monday the 20 I was just on with stars eight people going through this. That's why I remember but hopefully we'll see you at the booth, you know the video there.
Yeah. I don't know you guys doing AWS dream event. We are.
Well, yeah, he'll be lots of other great stuff that will be announcing again every 20 seconds in the movie another 20 seconds. Yeah. Absolutely.
It's one between now and then absolutely great stuff man. Thank you. All right get left here at cubecon.
We're live in Detroit. We're taking a break. We're gonna be back in a moment with another guest.
