GitLab’s DevSecOps Evolution with David DeSanto at RSA Conference 2024
GitLab chief product officer David DeSanto discusses the company’s transformation into a DevSecOps leader, emphasizing their recent acquisition of Oxeye and advancements in security integration throughout the software development lifecycle. The conversation highlights GitLab’s commitment to enhancing security measures, including real-time vulnerability scanning, AI-driven code analysis, and involvement with OpenSSF to define industry standards. With a focus on empowering developers and improving software supply chain security, GitLab continues to innovate and address the evolving needs of customers in an increasingly complex digital landscape.
Transcript
This is Textron tv. Hey, everyone. We're back here live.
It's, uh, what is it, about three o'clock? Well, no, it's only one 30 here in, uh, San Francisco at RSA conference. We're on Tuesday.
Seems start. There must be, you could tell when there's a lot of sessions going on because things quiet down here. Otherwise it's a little bustling.
Um, we're live on Broadcast Alley, which is a Moscone West. I'm joined by my friend David DeSanto. David, if you don't know, is the Chief Product officer at GitLab.
com and we started doing the DevSecOps event, people would say, what's a company like GitLab doing at a security show? Right. Or cyber show as they say now.
And I don't think people say that anymore. They Don't, not about GitLab certainly and not about DevOps in general. Yeah, Right.
We have a really nice booth over in the expo hall too. I I've seen that with a lot of advertisements and everything. And that started, I guess about three years ago, I think it was Ashley.
Yeah. Kramer got on Tech Drug TV with us and said, GitLab is a DevSecOps company, not a DevOps company anymore. Yeah.
A DevSecOps. Yeah. And that was sort of like the Microsoft trustworthy computing moment.
Mm-Hmm. For GitLab. Yeah.
Our, our first conversation was actually at RSA four years ago. That's when you and I first Right. Your first question to me was like, why are you here?
Yep. Absolutely. Yeah.
Who am I? What have I done? But now we don't ask that anymore.
We know why you're here. Yeah. GitLab is a DevSecOps company.
Dick GitLab, you know, when we look at the entire CICD process, the entire software development, life cycle software, supply chain, security and everything else, excuse me. GitLab plays a vital role in that. So I'm not going to obviously beat that dead horse.
We understand it, but you guys have some new stuff going on here. You made some announcements. You mentioned you're exhibiting here.
Is this the first time you're exhibiting? It's not the first time. I think what what's happened for GitLab is we've gone from being just that, as you said, DevOps platform.
If you think of SCM and CI and over the last several years and actually did a really great job helping rebrand GitLab as a company. Um, now there's this expectation that GitLab is actually a security company that does dev, like Dev, DevOps. DevOps, right.
Dev. And so yeah. For some of the things we've been talking about, I think the biggest things we just acquired another security company.
Uh, What, what do tell Yeah, Yeah. So their name is Ox. I, they're an Israeli based company.
Ox Ox, I-O-X-E-Y-E, Uh, Oxe. Yeah. I know them.
I've interviewed them several times. Yeah. So they're big, uh, Clement of fame was really two things.
Reachability of vulnerabilities. Yep. And their ability to do what they call code to cloud.
Mm-Hmm. Uh, scanning. And so that acquisition closed last month.
Fine. Didn't I? I didn't I missed that one.
Yeah. And someone hasn't been calling me over there. Uh, well, we'll, we'll take it up with, uh, my handler when we're done.
Yeah, Absolutely. Dave, you got a word for me there? So Ox I Oxy.
Yeah. So there No idea. There was two guys, basically the two co-founders.
Why are there two co-founders There? There's two Co-founders and there was a team, I think about 16 mm-Hmm. Well, I never got to interview them.
Okay, well we should make you, we should have to talk to them. Absolutely. But, uh, both Ron and Dean are fantastic.
Yeah. Security practitioners. But, uh, yeah, so they were a partner initially and we were seeing the value of what we could do together.
And so, uh, GitLab acquired Occi and the team is very excited to be here. They just did what they call a fast boot. They had the GitLab secure and govern teams, so that do security scanning and compliance, then GitLab, uh, and the team together in Europe.
And they planned out how they're gonna do the integration and so forth. So the first main thing is we're looking at accelerating our SA map, which includes the reachability. So for those who are unfamiliar, that allows you to validate that the vulnerability is actually exploitable and whether or not it's a false positive.
And with that, they're able to automatically detect that and mark them as such and excellent. That's the first part. The next part's the cloud or code to cloud where they are scanning at runtime that could moving into production.
And that's something that GitLab has not traditionally focused on, but we're excited to see where that can go. Well, so here's my crazy thing. Yeah.
I think there are two things missing in our SDLC, you know, lifecycle sort of security thing. One thing I'd like to see David is a, I'm gonna call it a, uh, a repo firewall. Okay.
That you cannot download anything from a repo, a repo, an artifact, a component or anything unless it goes through this firewall. And that firewall's gonna check to make sure it's the latest version. It's no, no, no vulnerabilities.
Maybe you run something in a sandbox or whatever. So, 'cause I think just doing that, filtering that stuff out at the source. Yeah.
And I don't know why repos don't do this, but, Well, I got good news for you. You took my idea. That's not good news.
My children need, you know, a living here. But what Do you think? Uh, well, I, what I would say, Alice, is I, I need to be able to feed my dogs.
Okay. Okay. We have kids.
I might two. I have an eight month old puppy. I was actually gonna ask you about it.
We talked about it last. I'll show, show you pictures when we're done. Awesome.
Yeah. Yeah. So, uh, Gil, I just have a dependency proxy built into it.
Okay. So you can only pull down packages that are authorized. Really.
Yeah. And then we're, our incubation teams are working on a dependency firewall, which would compliment that. That's exactly what I think the world needs.
I mean, for instance, we were doing a story the other day, even like docker hub images they get, right? Yeah. With malware And NP usually something, right?
Yep. So I think that's something that's desperately needed. And then the second piece of that is sort of what you're talking about here, Cloud, Right?
Yeah. Adapt, add that upload point, right? That's your other choke point.
It is. And by the way, I, what it does is it compliments some other features we recently released. So, uh, GitLab's always been run as part of the CI pipeline.
Mm-Hmm. So the security scans run at build time. Well, we wanted extend beyond that.
And now you get real time scanning of your dependency registry and your container registry. And so post Deployment, Uh, Or at deployment, Well, they're sitting in the registry and if we, uh, publish our, we update our vulnerability database a couple times a week, if we update the database and there's now a new vulnerability that you're vulnerable to, it'll alert you that it's in the registry and that it's in production. And so, GitLab, when I first spoke to you, uh, it would be almost four, a little over four years ago, I just remember it was right before the pandemic.
Right. And we had talked about can you get outta San Francisco? 'cause they were about to dock the cruise ship.
It Was 2020. Yeah. Right.
Uh, we were talking about with, uh, SaaS secret detection and das, and we've now expanded that to include container scanning, infrastructure code scanning. I love it. Fuzz testing API security.
Well, the fuzz testing, I think I remember. Yeah. But you know what you're talking about with registry.
Mm-Hmm. So it's not truly registry scanning, it's registry checking. You know, we were talking with Mitchell Ashley, our CTO off camera.
So Mitchell and I were at a company that we both helped co-found called Still Secure. And that was, uh, early two thousands. Mm-Hmm.
And we kind of pioneered Mac that worked access control. Yeah. And that's exactly, people used to ask, what's the difference between NAC and vulnerability scanning?
And that was exactly the difference. I'm not just scanning your infrastructure for vulnerabilities. I'm actually in our NAC product, we would go into the registry Mm-Hmm.
Now to endpoint and or servers. Yeah. We'd go into that registry and look at what the registry said you had Mm-Hmm.
And if it wasn't on that, call it a gold image. Yeah. Golden image.
We would, you know, using 8 0 2 1 x, we'd prevent you from getting on the network, take you off the network, put you in quarantine, remediation or what have you. It sounds a lot like that. Yeah.
What, how I look at it as is that, you know, software's become even more complex. Yes. There was a great paper, it's probably about five, six years old now, but it was an analysis of the last 20 years of security vulnerabilities.
And it talked about how enterprise applications were growing at like 10 x code base. Mm-Hmm. Vulnerabilities were growing at like a half a percent per year in size.
And the risk of what that is, and when you think about someone like GitLab, who's trusted by more than 50% of the Fortune 100 to secure their software, you're in the situation where that could be a lot of microservices, a lot of applications. We have customers who talk about having tens of thousands of applications. And so the best way to help you secure that is to give you the visibility into what's in your registry, what's running in production.
Absolutely. Yeah. Absolutely.
Um, this available now. Yeah. So the real-time scanning is available now.
If you are using GitLab Ultimate, you can go in and enable it. The ox I integration will happen over the next nine months. The team is focusing first on integrating their SaaS scanner in first, replacing our existing, and then we will then start on the reachability and longer term the, the code to cloud.
But I love it. It, I'll tell you there, there's always excitement when, when we do an acquisition both internally and the company who's joining GitLab. There's just a lot of excitement about what this could actually mean for DevSecOps.
I, I, look, I love the Occi story. I love, you know, both of those, the two co-founders were two bright young men. Yep.
Um, so that's our canine dogs here. Yeah. They wanna join the conversation.
Yeah. They, they're on next they said David's about out of his 15 minutes, uh, mic him up. Yeah.
Um, but anyway, yeah. So I ox I was one of the announcements. What else do you have?
Yeah, so we've extended GitLab Duo and what I can do for ai. And, and so for those who know GitLab duo's, our suite of AI features across DevSecOps Mm-Hmm. And, uh, since the last time we spoke and we're showing off in the booth today.
So if you're here at RSA, stop by, if not, you can see the demo on the website. We're showing off, uh, duo's ability to auto resolve vulnerabilities. Love it.
And so now for developers, it's not just helping them understand why it's a vulnerability, but now with a single button they can click and have duo refactor the code and remove the vulnerability. I Love that. And so what we're realizing is that for customers to get the acceleration they need, like we, at our time of our IPO, Sid said he was quoting a Mark Andreesen, like every company will have to become a software company.
Yeah. I think everyone now is have to become an AI company to stay competitive, but no doubt. And giving them the power of what Gulab Doo can do, not just for creating code, helping 'em with playing, but now helping 'em auto resolve vulnerabilities.
You're starting to empower the entire team and that's where you get your acceleration. I love that. Yeah.
Very cool. Yeah. What else we got David?
Yeah, so I would say the last thing is stay tuned. We've been focused a lot on software supply chain security. We see that as fundamental to how people deliver software.
It is. Uh, we recently, uh, took a, a more prominent role with the open SSFI joined the board a couple months ago and we're really looking forward to how we can help define better software supply chain security standards for the industry. Amen.
Because I mean, I know they've had some reorg in open SSF I'm glad to hear that GitLab is, is actively involved in there now. Yeah. We're a general member and I joined the board.
You are? Yep. Good for you.
Yeah, I'm excited about it. I, I knew some of the board members there. Um, I don't know if they've stayed or left 'cause they've left some companies, but we'll talk about it.
Yeah, we can talk about it, but I think there's a tremendous opportunity to make it happen there. Yeah. I mean, ultimately like our goal, so we've been focused initially on shifting security left and helping you see your vulnerabilities on the dev side.
We then started talking about the ops side and Yeah. Leveraging things like our API scanning and so forth on production. And now it's about getting that full, uh, connected environment.
The feature we just announced in our last release was the ability to block secrets before they're even pushed that pre-commit time. Very powerful. Absolutely.
You wanna extend that to now being also, uh, web signing. If you're doing stuff within the ui, being able to give you a full SBO m not just for the software that GitLab is built, but allow you to import other Applications. That's right.
You gotta put everything in there. Yeah. And then finally, just continue to extend the visibility you can get today.
Right now you can see if there's a compliance violation that's occurred. I wanna take that further and get you into like the actual, call it the data digital forensics component of that to better understand what happened, why it happened, and how to prevent it. And so if you start to look at the things we've talked about, whether it's oxide, whether it's the pre-commit, secret scanning, and the container scanning both, or the registry scanning both container dependency and you start to see like where that can go.
Uh, our goal is to really give someone a single pane of glass into their, their full software development life cycle, including the health of their software supply chain. I love it. Yeah.
So you, what you're trying to tell me is you haven't been very busy. You get Yeah. I mean, I'll, I'll, I'll be honest.
You fake, I've been lo fake. Yeah. Yeah.
It's actually funny. I think every, every conversation we have, it's like, when has David been home? Right?
So this is the end of five weeks of travel. I got to go around the world, meet with a lot of customers. It's very interesting to see how re regardless of where you live in the world and who you work for, there's a lot of common themes.
Yes. There is. You know, you're worried about developer productivity.
You're worried about security. Security. You're worried about visibility and really about the guide rail guardrails and controls.
Yeah. And whether that was visiting customers in Paris, London, and Germany across the us it's really interesting to see how GitLab is making a difference for, for our customers in the industry. Like Walt Disney said, it's a small world after all.
It is. But yeah, we've gone from first conversation. David, why, why is GitLab at RSA to GitLab has put the s second DevSecOps Excellent, man.
I love it. Yeah. David Desto GitLab here live at RSA.
Excuse me. We're gonna take a break as we're head into our afternoon coverage of our first second day of coverage here at RSA. Stay tuned.
We'll be back.