The Lab with Brendan O’Leary EP 20
Senior developer evangelist Brendan O’Leary tells us about this month’s GitLab release.
Transcript
Hello friends and welcome to the lab a monthly show where we look at the latest and greatest developments in software development devops and the cloud I'm your host Brendan O'Leary and coming today from a seasonally cool Annapolis, Maryland on the east coast of the United States. And for those of you don't know me. I'm a Staff developer evangelist to get lab.
6 releases out and brings cutting-edge new capabilities to get Labs SecOps platform. We have exciting new product updates that are going to help developers and other folks collaborate and deliver software more securely. 6 updates and also discuss gitlab's latest enhancements to security and governance and the solutions around that and I have with me here today get lab directive product management Hillary Benson in front of the program who will join us later in the show to discuss some exciting new security features.
6 update. First we introduced get abuse rate limiting. This is really helpful feature that notifies administrators want a user downloads or clones more than a specified number of repositories in a group or subgroup within a given time frame and you can also automatically ban users who exceed that rate limit so that those users won't be able to access, you know, the the group or it's not public subgroups.
Now, of course that won't affect unrelated groups to that but it will help you kind of curb if someone's trying to download a lot of data from from your group and these bands are permanent by default but a group of administrator can unban and affected user if it was kind of an erroneous band and they were doing that for some legitimate purpose. Also have new group and subgroup level scan result policies. So now you can manage those scan result policies at the group level or at the subgroup level and these policies then automatically flow down and applied all the projects inside of a group which makes it a lot easier to kind of enforce those policies uniformly for a large organization that might have a large number of projects or groups within gitlab.
And so to get started just in your group or subgroup if you're the owner of it, you can link the associated security policy on the security compliance policies page. To kind of go along with that comes a scan execution policy support for dependency scanning. So you can now require dependency scanning to run on you know, a regular schedule or as part of the Project's CI/CD pipelines independent of what is inside of the gitlab ciml.
This will allow security teams teams to manage those scan requirements separately and and universally without allowing developers to then, you know forget or change those configurations. It's also very easy to get started by creating a scan execution policy under security and compliance again and in the policies page. One that is a near and dear to my hardest support for special characters in ci/cd variables.
So previously it was very difficult to use, you know, like the dollar sign character and available variable because that normally signifies the start of another, you know environmental variable. And so gitlab would interpret it and try to expand it. But in in this release, we added an expand keyword which will allow you to say, you know, this is a raw variable that we don't want expanded it it has, you know a dollar sign in it and this raw variable can contain, you know, any special characters and isn't you know that we don't try to expand it more passing that on to the runner.
We also have an increase in support in the rules exist configuration for ci/cd variables. So once you get to more complex, you know gitlab CI configuration. It can be very difficult to kind of maintain and scale that at a large scale.
But by adding support for ci/cd variables within the rules exist keyword, you can now use variables for things like paths or file names and that allows you to easily have a single source of Truth by storing, you know, those frequently used variables somewhere and then ensure consistent Behavior across all of your pipelines and make that configuration a lot easier to manage. So that's really exciting update. And then finally, you know, really big update and maybe the large one.
It's hard to pick a favorite. But as a dashed API analyzer for on-demand dashed API scans, so Now we can use this task API analyzer for any on-demand dashed API scan and in previous version. The analyzers are used in these on-demand scans was the Legacy version of our Das to analyzer but our internal benchmarking shows that our dashed API analyzer finds more vulnerabilities has a lower false positive rate than our Legacy analyzer.
So we're really excited to bring this to the on demand scans. It also introduces new functionalities such as graphql scans support for authentication tokens that might expire scans using a collection from Postman or har files. So this is really, you know, a fantastic update and while we're you know switching with the switch to the dashed API analyzer some of that functionality is already available in the on-demand site profile in addition to using an open API specification inside profile to define the API test you can now also use a postman collection or hard file to make sure that your test gets, you know, all of the API coverage that you expect and and manage that a lot easier.
And also added basic authentication as another option for on-demand API scans, you know previously we were using token based only and authorized on in the authorization header, but now you can use basic auth as well. And next up will be work on adding graphql support to those on-demand API scans. And so look for a lot more improvements in the next few releases as we incorporate more of this Advanced functionality of the dashed API analyzer into the on-demand task ends.
6 fantastic improvements both to managing complex CI CD pipelines as well. As you know, this huge step forward with dashed Dynamic application scanning. 6 and read about all of the Fantastic improvements and that you have course go to the gitlab blog and look for the blog post that has every one of the improvements and changes listed right there.
And now I'm really excited to dive into gitlabs newly announced, you know, security and governance features, but not under the Hillary Benson who has previously joined the lab as a guest a few times and has a lot to tell us about this new product announcement Hillary. Welcome back. Thanks for having me written.
I'm happy to be back. Yeah, always glad to have you on. Now hurry, could you tell our listeners a little bit about you know security and governance?
What is it? And why does it matter and and how's gitlab looking at this the space? Yeah, of course.
So inherently, there's usually quite a lot of complexity involved and making sure that you have the right approach the right processes and the right Tooling in place to build secure software that can continuously meet requirements both for your organizations internal security policies as well as any regulatory requirements that you might need to comply with. So The concepts of security and governance within gitlab are all about reducing that complexity. So we're very laser focused on enabling our users with a platform that's outfitted to help you implement a comprehensive Dev stick Ops program that not only lets you enable or lets you find and fixed security issues early in the development process, but also provide the native capabilities to help you manage your Global Security risk with built-in security policies and compliance Frameworks and system of checks across the entire development lifecycle to ensure that you're your software supply chain is as secure as possible.
So our recent product announcement highlights number of features, most of which are are available now in the product today that can provide, you know, Concrete Solutions for users in each of those areas. Yeah, that's that's really exciting. And and I I know I've been looking at this announcement.
There's a lot of different exciting updates that are part of it. But you know, what are some of the specific changes or updates and and what are you most excited about when it comes to you know this kind of broad category? Yeah, there's really a lot of great stuff that's available today.
So I think from from our most recent announcement the features, you know broadleaf fall into three buckets. There's software supply chain security finding and fixing vulnerabilities and compliance. So in the first bucket software supply chain security, I think often the first thing that comes to mind for most people when they think of supply chain security is managing dependencies and building that basic, you know software bill of materials.
So earlier this year we made it easier for gitlab users to generate an export software developmental materials or s-bomb for their projects using native data from gitlab. And so as we continue to evolve our s-bomb capabilities, we're looking to provide users with the way to leverage third-party tools that they might be using to do the same thing. And then I think another big aspect of supply chain security is in, you know, being able to prove the authenticity of any software artifacts that you're building.
So today get lab Runner can produce a SLSA to compliant attestation for any artifacts that it produces and then going forward we'll look to have the runner automatically generate those attestations for every build. So it's a real seamless process. So those are the big things going on in this pie change security bucket.
We have a lot of other stuff going on there as well. But these are the kind of highlights. In that second category of finding and fixing vulnerabilities, we've delivered a number of really important improvements recently.
There's really too many high to highlight individually, but generally speaking we've been very focused on reducing exposure to false positives improving our rule sets streamlining user experience. There's a lot going on there. There's one feature.
I want to highlight specifically earlier this year. We introduced what we're calling Integrated Security Training into our developer workflow a very common problem organizations face is actually enabling their development teams to take action to resolve security findings. There's a number of challenges that are sort of baked into that but part of the challenge comes down to very pointed security education for developers.
So the idea behind Integrated Security Training is to provide developers with the information that they need to understand the risk behind of vulnerability. What causes it and how to fix it at exactly the moment that it's most Relevant, which is when they've actually introduced some bit of insecure code into an MR that they're working on. So this pulls security education that is often kind of high level and sort of esoteric for folks and makes it very actionable and relevant for developers by putting it in the context of their day-to-day work.
And then finally the last bucket of updates I want to touch on are around our compliance offerings. So this is another major area of ongoing Focus for us and there's really a laundry list of features to touch on here from streaming audit events to you know, enabling folks to require two person approvals in merge requests based on certain criteria the ability to set specific password requirements for your users. We also recently completed our fips 140-2 compliance effort.
So there's been a lot going on here and then going forward we're very focused on making it easier to manage compliance at scale. So you see a lot of that coming. So for example, we have some work coming up on customizable roles and permissions that will make it easier to scope who has access to what so that's quite a lot that we've had going on.
But those are those are the major highlights. Yeah. No, that's a lot and and you know, it's a large area security compliance and it's one where I think I'm really excited to see us taking all these, you know, big steps forward and kind of looking at the full breadth of you know, security and compliance and that security education you touched on is really key.
I know back when I was trying to develop software for the federal government, you know, you have a lot of times where you get to the end of a cycle and have all of these, you know security findings and it's like none of the context is there right? And so putting that in context really enables developers to learn and make a smarter to assessment of you know, maybe something is a false positive or maybe we haven't thought through how Something's Gonna work having that happen. When you're in that context of the merge request that's making the changes.
It's just so critical, you know, our deaf Stack Up survey the sheer showed that you know developers and lots of folks throughout the desk stuck off space or feeling more and more responsibility for security. This is a way we can help enable that And then you also started with something. There's been a lot of discourse about you know in the past year and a half two years supply chain security, you know, is that discourse?
What's what's driving these changes or what do you think about that when you when you look at the market? Yeah, that's definitely a big part of it. So I think with kind of the wide scale supply chain attacks over the last couple years and you know, the additional standards that folks are working on to try and get a grasp on how to address those attacks.
I think you know organizations are very aware of their security postures and our prioritizing that and at the same time, you know, we're seeing broader organizational ownership of security then was the case in the past, right, you know these days development operation team operations teams are you know owning significant pieces of the security puzzle as much as the security team is and so for most people's security is already kind of right at the center of their software development lifecycle and their product strategy and if it's not it probably should be So forget lab, I think that means making devops look more and more like SecOps every day. Right? And so one of the one of the benefits I think of our single platform approach is that it really directly facilitates a lot of that evolution in a very natural way because it's where these different groups are already working and we're fighting that's driving a lot of value for for our users our customers and partners.
And in fact in our our annual the secops survey this year, we found that you know, as you're touching on actually that security was the highest priority investment area for organizations and you know nearly 57% of Security Professionals stated that their organizations have kind of already shifted security left or they plan to this year. And so the SecOps philosophy is definitely, you know going into practice and folks are always looking for ways to make it easier. Yeah, that's interesting.
You mentioned shifting left something. We've heard a lot as well. Is that still something that you know folks that may have a devops practice or or are working on there is that's shifting left still something that's key to like the bigger picture of devops.
Do you think? Definitely, I think so. Yeah, I should shifting left is a critical part of it as as organizations try to move to more of a SecOps model of developing software, you know bringing security testing earlier in the development life cycle is always going to be a critical critical part of that process.
And so that's why I get lab, you know, we're continually focused on reducing the friction associated with that process and trying to make it as easy as possible to test as early as possible. Makes sense. Well great.
Well, Hillary your insights are always so appreciated. It's been great having you on the lab again, and and we can't wait to have you back. Thanks, my friend.
Yeah. Thank you. com or check out our latest blogs and press releases.
And thanks so much again for watching me watching today and joining us. You can find me on the internet at O'Leary crew most places. If you have an idea for a future episode or want to discuss anything from today's episode more detail.
Feel free to reach out. Again, the lab is produced monthly. So thanks again for joining us and I'll see you next month in the lab.
Happy holidays and stay safe.





