GitLab
GitLab
  • 1 463
  • 5 825 426
GitLab 17 - Streamlined SAST and Android Dependency Scanning
GitLab 17 introduces Streamlined SAST and Android Dependency Scanning making for a more consistent and configurable security experience. Learn more about GitLab 17 by attending our virtual launch event (June 27): about.gitlab.com/seventeen/
OUTLINE:
00:00 - Introduction
01:16 - Adding Scanners to Pipeline
01:44 - Scanner Results in Merge Request
03:20 - Software Bill of Materials (SBOM)
04:10 - Conclusion
USEFUL LINKS:
- GitLab 17 Blog: about.gitlab.com/releases/2024/05/16/gitlab-17-0-released/
- GitLab 17.1 Blog: about.gitlab.com/releases/2024/06/20/gitlab-17-1-released/
- Support Languages and Frameworks (SAST): docs.gitlab.com/ee/user/application_security/sast/#supported-languages-and-frameworks
- Android Dependency Scanning CICD catalog: gitlab.com/explore/catalog/components/android-dependency-scanning
DEMO PROJECTS:
- Android Hello: gitlab.com/gitlab-da/tutorials/security-and-governance/mobile/android-hello
Thanks for watching! Be sure to subscribe and follow @awkwardferny and @gitlab on twitter for similar content.
Переглядів: 75

Відео

GitLab Duo Test generation
Переглядів 2,3 тис.Місяць тому
GitLab Duo Test generation Test generation automates repetitive tasks and helps you catch bugs early. To learn more: docs.gitlab.com/ee/user/gitlab_duo_chat.html#write-tests-in-the-ide
GitLab Security and Governance Feature Overview
Переглядів 586Місяць тому
GitLab is the most comprehensive AI-powered DevSecOps Platform which empowers your teams to balance speed and security by automating software delivery and securing your end-to-end software supply chain. Our platform provides all the features necessary for your organization to secure your complete application lifecycle, manage threat vectors, adhere to compliance requirements, and much more. OUT...
Add Security Scanning to your CI/CD pipeline in under 1 min
Переглядів 484Місяць тому
GitLab is the most comprehensive AI-powered DevSecOps Platform allowing you to deliver better, more secure software faster! GitLab allows you to easily integrate security scanners into your pipeline using templates. Security scanner coverage includes: * Source code * Dependencies in your projects or container images * Vulnerabilities in a running web application * Infrastructure as code configu...
GitLab Duo: Your end-to-end AI partner for faster software development
Переглядів 1,3 тис.Місяць тому
GitLab Duo is your end to end AI partner for faster more secure software development. From planning, coding, and securing to deploying it supports developers at every stage of the software development life cycle. Learn more at: about.gitlab.com/gitlab-duo
Southwest fala sobre o futuro da IA - (Portuguese-Brazil)
Переглядів 90Місяць тому
O CISO da Southwest diz que não vê a inteligência artificial substituindo os desenvolvedores, mas espera que ela forneça soluções que facilitem seu trabalho.
Novo no GitLab, vamos explorar - GitLab Innovation Pitch Competition - (Portuguese-Brazil)
Переглядів 120Місяць тому
Novo no GitLab, vamos explorar - GitLab Innovation Pitch Competition Visite gitlab.devpost.com/ para saber mais sobre o GitLab Innovation Pitch Competition. Você pode encontrar recursos sobre como contribuir com o GitLab em about.gitlab.com/community
Nasdaq: Um caso de sucesso GitLab - (Portuguese-Brazil)
Переглядів 50Місяць тому
Ouça Stephen Cooper, Diretor Sênior de Engenharia de Software da Nasdaq, explicando como a GitLab está ajudando a Nasdaq a alcançar sua visão de transformação na nuvem
Eliminando riscos com feature flags - (Portuguese-Brazil)
Переглядів 53Місяць тому
Eliminando riscos com feature flags Com feature flags, você pode implementar os novos recursos da sua aplicação em produção em lotes menores. Você pode ativar e desativar um recurso para subconjuntos de usuários, ajudando a alcançar o Continuous Deployment (CD). Feature flags ajuda a reduzir o risco, permitindo que você faça testes controlados e separe a entrega das funcionalidades do lançament...
GitLab Duo - Explicação da vulnerabilidade - (Portuguese-Brazil)
Переглядів 30Місяць тому
GitLab Duo - Explicação da vulnerabilidade A explicação de vulnerabilidades ajuda os desenvolvedores a compreender e corrigir vulnerabilidades com mais eficiência e a aprimorar suas habilidades, permitindo-lhes escrever códigos mais seguros. Veja-o em ação neste pequeno vídeo. Leia mais aqui: docs.gitlab.com/ee/user/application_security/vulnerabilities/index.html#explaining-a-vulnerability
GitLab Duo - Explicação do código - (Portuguese-Brazil)
Переглядів 71Місяць тому
GitLab Duo - Explicação do código A explicação do código ajuda você a entender o código, explicando-o em inglês. Leia mais aqui: docs.gitlab.com/ee/user/ai_features.html#explain-code-in-the-web-ui-with-code-explanation
GitLab Duo - Revisores Sugeridos - (Portuguese-Brazil)
Переглядів 43Місяць тому
Revisores sugeridos do GitLab Duo Os revisores sugeridos ajudam você a receber avaliações mais rápidas e de maior qualidade, encontrando automaticamente as pessoas certas para revisar uma Merge Request. Veja-o em ação neste pequeno vídeo. Leia mais aqui: docs.gitlab.com/ee/user/project/merge_requests/reviews/index.html#gitlab-duo-suggested-reviewers
GitLab Duo Code Suggestions - (Portuguese-Brazil)
Переглядів 58Місяць тому
GitLab Duo Code Suggestions O Code Suggestions permite que você escreva código com mais eficiência, visualizando sugestões de código enquanto você digita. Veja-o em ação neste pequeno vídeo. Leia mais aqui: docs.gitlab.com/ee/user/project/repository/code_suggestions/index.html
Southwest Airlines' developers fly with GitLab
Переглядів 1,3 тис.2 місяці тому
Southwest Airlines Co., the world's largest low-cost carrier, was looking to make developers’ jobs easier. The organization did just that by adopting GitLab’s platform, which has meant eliminating time-consuming and repetitive tasks from developers’ workflows and increasing their ability to focus on bigger projects. GitLab also has given them a standard way of moving code to production, and con...
GitLab Duo Chat
Переглядів 1,4 тис.2 місяці тому
GitLab Duo Chat Chat helps you quickly identify useful information in large volumes of text, such as documentation. To learn more: docs.gitlab.com/ee/user/gitlab_duo_chat.html
GitLab Duo Value stream forecasting
Переглядів 3972 місяці тому
GitLab Duo Value stream forecasting
GitLab Duo Code review summary
Переглядів 9262 місяці тому
GitLab Duo Code review summary
GitLab Duo Discussion summary
Переглядів 4662 місяці тому
GitLab Duo Discussion summary
GitLab enables CACI to deliver software faster
Переглядів 8373 місяці тому
GitLab enables CACI to deliver software faster
Meet GitLab Duo
Переглядів 4,5 тис.3 місяці тому
Meet GitLab Duo
GitLab Duo Vulnerability explanation
Переглядів 6633 місяці тому
GitLab Duo Vulnerability explanation
Tutorial: Integrating a custom security scanner with GitLab
Переглядів 1,5 тис.4 місяці тому
Tutorial: Integrating a custom security scanner with GitLab
Eliminating risk with feature flags
Переглядів 3 тис.4 місяці тому
Eliminating risk with feature flags
Southwest talks about the promise of AI
Переглядів 3765 місяців тому
Southwest talks about the promise of AI
GitLab Continuous Integration Overview (v2)(HD)
Переглядів 1,6 тис.5 місяців тому
GitLab Continuous Integration Overview (v2)(HD)
Implementing Custom Roles and Granular Security Permissions with GitLab
Переглядів 7505 місяців тому
Implementing Custom Roles and Granular Security Permissions with GitLab
Introduction to the Principle of Least Privilege with GitLab
Переглядів 3275 місяців тому
Introduction to the Principle of Least Privilege with GitLab
Combine GitLab Flow and GitLab Duo for a workflow powerhouse
Переглядів 1,6 тис.5 місяців тому
Combine GitLab Flow and GitLab Duo for a workflow powerhouse
GitLab Duo -- Demostración de AI-Powered DevSecOps
Переглядів 5485 місяців тому
GitLab Duo Demostración de AI-Powered DevSecOps
Aprobaciones de Merge Request - Controles de Lanzamiento (HD) - (Spanish-LATAM)
Переглядів 2725 місяців тому
Aprobaciones de Merge Request - Controles de Lanzamiento (HD) - (Spanish-LATAM)

КОМЕНТАРІ

  • @tigranrostomyan9231
    @tigranrostomyan9231 5 днів тому

    This is CRAZY. Thank you so much!

  • @samgreaves8038
    @samgreaves8038 6 днів тому

    according to this advert you can get gitlab duo to "instantly generates the method" and shows it adding it to the codebase. from what gitlab duo actually tells us in the web ide that this isnt possible, is this false advertising?

  • @user-pq1qe2jf2y
    @user-pq1qe2jf2y 8 днів тому

    Now i haven't button "Github" when importing, only gitlab, bitbucket cloud, frogBugz Gitea Repository by URL and mainfest((( Why?

  • @SubhamJena-of7vf
    @SubhamJena-of7vf 14 днів тому

    Is the component catalog have to be public to be used by others ?

  • @sparshgupta7897
    @sparshgupta7897 15 днів тому

    Complete waste of time

  • @RO-NOC
    @RO-NOC 22 дні тому

    to old

  • @houssemeddinekhammassi3285
    @houssemeddinekhammassi3285 23 дні тому

    how could we reach out to you guys ?

  • @globalcmc
    @globalcmc 24 дні тому

    1 vote for gitlab, i have used both. Gitlab is harder to understand but when you have it, it feel more controll and flexible than jenkins, with better UI. About runner, i love and still use docker runner for almost all my pipeline and jobs with all environment and things setup within build image, and clean start make it your build clean as possible !

  • @N3omega
    @N3omega 25 днів тому

    I like nintendo e shop so get kraken squids

  • @shaikmahammadgouse8482
    @shaikmahammadgouse8482 27 днів тому

    Please share the Gitlab Url. It would be more helpful..

  • @gamertechkid1490
    @gamertechkid1490 28 днів тому

    This video needs to tone down the background music

  • @andrejflieger4182
    @andrejflieger4182 28 днів тому

    what about the kubernetes agent? What permission does / must the agent have, cluster-admin? If so I think it could be abused, couldn't it?

  • @andrejflieger4182
    @andrejflieger4182 28 днів тому

    why does the secret for the deploy token go to default namespace?

  • @emimassey
    @emimassey 28 днів тому

    Well done, I do agree the approach that GitLab is following to integrate the value stream mapping nativelly

  • @ahmadalwazzan384
    @ahmadalwazzan384 28 днів тому

    Can you provide the example code?

  • @christophkiefer
    @christophkiefer Місяць тому

    Hi Thanks for the video. I am working with GitLab on a daily basis. What I don't quite understand is why one wants to connect to the remote machine when you DON'T see the code of the repository any more? I think the whole point is to use that development machine to work on the code you showed at the beginning. So I would expect that the code you showed as, at the beginning, is mounted into that remote development environment. Any further advice, hints, references are highly appreciated.

  • @ansadahmad1958
    @ansadahmad1958 Місяць тому

    Thank you sir for this video! Your efforts into making a simplified free video is much appreciated by us all curious learners!! <3

  • @marcobaldi138
    @marcobaldi138 Місяць тому

    I wonder if it takes into account the repository context. For example, Copilot never mocks the common things I usually mock, so while it is kind of useful it still needs elbow grease.

    • @N3omega
      @N3omega 25 днів тому

      Who works for nintendo e shop yeah i push stuff too lol haha

  • @keenheat3335
    @keenheat3335 Місяць тому

    difficult part is usually from async code and mockup prior function output or service behavior. The test setup part, baiscally. Espeically hard if the code is not statically determine or rely on 3 party library that compile to a binary. would amazing if they can do that

    • @N3omega
      @N3omega 25 днів тому

      Who works on nintendo e shop yeah ik how to push

  • @CaunaRoblesyuriCristian
    @CaunaRoblesyuriCristian Місяць тому

    Gracias!!!

  • @NikitaThombre-we4rb
    @NikitaThombre-we4rb Місяць тому

    did anyone provide me whole workflow explain 0.12 image

  • @TaiiwoLlort
    @TaiiwoLlort Місяць тому

    Did anyone notice the code snippet generated at 0:58 makes no sense? Why is it declaring the method twice like that? It also got the name wrong, adding an "s" to the end

    • @TaiiwoLlort
      @TaiiwoLlort Місяць тому

      Also the method returns price.size()? Where price is defined in the previous method _as a double_? How you gonna get the size() of a double? Why can't you guys double check the code generated in your demos? Would give it much more credibility.

    • @michiman6757
      @michiman6757 Місяць тому

      @@TaiiwoLlort Could 'Price' and 'Prices' just be to different variables that are poorly named. Prices is an array while Price is a Int. Check if array is empty, if not then continue to next line? Edit: nevermid. saw the newly generated code calling for price.size(). Yeah that doesn't make much sense now

  • @eonoire
    @eonoire Місяць тому

    Why do you have to force shitty ai into everything?

    • @DaBeanBro
      @DaBeanBro Місяць тому

      AI is incredible. Not just for software development, but in computer science classes that i've gone to it's apparently being integrated into medicine, education and even the manufacturing industry. AI is literally the most influential technology of our time. It is changing the world. Emerging technologies never start perfect, or even usable for that matter. Give AI 5 years and get back to me, I urge you to tell me it's so shitty if it solves cancer or something.

    • @TaiiwoLlort
      @TaiiwoLlort Місяць тому

      To answer your question, it's so that your app doesn't become irrelevant in comparison to alternatives. Github has copilot, so gitlab _has_ to have AI otherwise it's comparatively worse. Even if it's not as good, or completely different, it soothes the shareholders. Tl;dr: money

    • @eonoire
      @eonoire Місяць тому

      @@DaBeanBro if you think ai will solve cancer you have lost your mind.... it's just another shitty thing to make products worse and labour conditions worse to increase profits. I'm sure it will have it's usecases but as it stands. it's overhyped and it will never be able to live up to the unrealistic expectations.

  • @jackson159
    @jackson159 Місяць тому

    Why gives me this Devin Vibes

  • @aliencord8259
    @aliencord8259 Місяць тому

    people still use gitlab? word

    • @qazyhn94
      @qazyhn94 Місяць тому

      what should be used?

  • @TomasRohrer-dq1sx
    @TomasRohrer-dq1sx Місяць тому

    Honestly, I'm a bit disappointed that something like "AI" is needed to get a better suggestion for reviewers 🙄. On top of the list, I will have code owners by default and people with whom I mainly collaborate. Sadly, this is not the case, and you spend much time writing their initials 🤦🏼‍♂.

  • @MrPtbr
    @MrPtbr Місяць тому

    This would be a good company to invest into, but sadly ceo's and insider shares sell every week. Dont recommend

  • @MdAlihossenblogevideo
    @MdAlihossenblogevideo Місяць тому

    ❤❤

  • @EricEricRamos
    @EricEricRamos Місяць тому

    Free To All

  • @OwenAlekos-mh7yw
    @OwenAlekos-mh7yw Місяць тому

    A ten year initial passed and 10 year launch this year. Regarding how it is a game changer for the new millennium and potentially tons of people haven't seen nor heard about their associations and contributions... Ruby tower of Oklahoma and how the business could be associated with nationality and heritage and lineage being discussed regarding Ukraine. Ukraine war currently and Crimea railroad... Could be a reference to Washington DC as though it's Azerbaijan representing USSR for the railroad, like it is about more than railroads but new roads and bridges to Oklahoma city... Huge topic about insurance socially and financially. In a way that could be a large modifier before the end of the first quarter of the new millennium. 2024 and checklists completed before 2025 is here and active and everything is available and opened...

  • @Fazal828
    @Fazal828 Місяць тому

    hilarious!

  • @worawat_dot_com
    @worawat_dot_com 2 місяці тому

    GitLab pipelines are elite (send me merch please. I'm out of stickers)

  • @LeoLiu-le1fm
    @LeoLiu-le1fm 2 місяці тому

    great customer story!

  • @user-so5dx7gb2u
    @user-so5dx7gb2u 2 місяці тому

    great feature!

  • @matej.m.rejsek8537
    @matej.m.rejsek8537 2 місяці тому

    Gitlab requires your phone number (with zero details given w/respect to how they disclose that data) to even get read access to codebases. Big Nope.

  • @matej.m.rejsek8537
    @matej.m.rejsek8537 2 місяці тому

    Gitlab requires your phone number (with zero details given w/respect to how they disclose that data) to even get read access to codebases. Big Nope.

  • @MdAlihossenblogevideo
    @MdAlihossenblogevideo 2 місяці тому

    ❤❤❤❤

  • @lolaswift111
    @lolaswift111 2 місяці тому

    Does anyone that if it's possible to do a per project integration? because potentially if gitlab user knows the issue id, it can push changes to any jira issue in any jira project but we want isolation. thx

  • @halimatoubah3172
    @halimatoubah3172 2 місяці тому

    Thank you, this helped 🙂

  • @hrl_fd
    @hrl_fd 2 місяці тому

    🎉🎉🎉🎉🎉

  •  2 місяці тому

    What about "git request-pull" command? Isn't the propelly way to create a merge request through command line?

  • @LeoLiu-le1fm
    @LeoLiu-le1fm 2 місяці тому

    great feature!

  • @pappaflammyboi5799
    @pappaflammyboi5799 3 місяці тому

    Umm, yeah, duh! Where have you been for the last 25 years? Have you never used concurrent versioning, or revision control systems?

  • @bruno.hoffmann
    @bruno.hoffmann 3 місяці тому

    great job!

  • @RahulPrajapati-bl1tx
    @RahulPrajapati-bl1tx 3 місяці тому

    Please give gitlab repo for reference

  • @andrel.a.cbittencourt5835
    @andrel.a.cbittencourt5835 3 місяці тому

    Simplest solution ever is to create a "budget concept" similar to SRE's error budget. Ex: Depending on the agreement between Product & Engineering a team might have 25% of the budget for Tech Debt & 40% for new features and 10% for maintainance. Those agreements helps to bring balance and transparency to backlog management and expectation aligment. In some orgs the most difficult part is to get an agreement between Product&Engineering as the incentives in the system prevent such deeper level of collaboration. The wrong incentive is that Product is incentivised to produce features and not high quality software.

  • @Headinthecl0uds
    @Headinthecl0uds 3 місяці тому

    great content

  • @shrutiawasthy2978
    @shrutiawasthy2978 3 місяці тому

    How to send email notifications to the set approvers to let them know that merge request is awaiting their approval?

  • @soportelinux1099
    @soportelinux1099 3 місяці тому

    hello friend, how can I add a favicon to my web in gitlab pages?