Secure your application
GitLab can check your applications for security vulnerabilities.
Getting started
Overview of how features fit together.
Application security
Scanning, vulnerabilities, compliance, customization, and reporting.
Compliance
Compliance features.
Detect
Vulnerability detection and result evaluation.
Triage
Vulnerability separation by status.
Analyze
Vulnerability analysis and evaluation.
Remediate
Root cause determination and analysis.
Security configuration
Configuration, testing, compliance, scanning, and enablement.
Container Scanning
Image vulnerability scanning, configuration, customization, and reporting.
Dependency Scanning
Vulnerabilities, remediation, configuration, analyzers, and reports.
Comparison
Dependency Scanning compared to Container Scanning.
Dependency List
Vulnerabilities, licenses, filtering, and exporting.
Continuous Vulnerability Scanning
Scanning, dependencies, advisories, and background jobs.
Static Application Security Testing
Scanning, configuration, analyzers, vulnerabilities, reporting, customization, and integration.
Infrastructure as Code (IaC) Scanning
Vulnerability detection, configuration analysis, and pipeline integration.
Secret detection
Detection, prevention, monitoring, storage, revocation, and reporting.
Dynamic Application Security Testing (DAST)
Automated penetration testing, vulnerability detection, web application scanning, security assessment, and CI/CD integration.
API Security
Protection, analysis, testing, scanning, and discovery.
Web API Fuzz Testing
Testing, security, vulnerabilities, automation, and errors.
Coverage-guided fuzz testing
Coverage-guided fuzzing, random inputs, and unexpected behavior.
Security Dashboard
Security dashboards, vulnerability trends, project ratings, and metrics.
Offline environments
Offline security scanning and resolving vulnerabilities.
Vulnerability report
Filtering, grouping, exporting, and manual addition.
Vulnerability Page
Vulnerability details, status, resolution, and linking issues.
Vulnerability severity levels
Classification, impact, prioritization, and risk assessment.
GitLab Advisory Database
Security advisories, vulnerabilities, dependencies, database, and updates.
CVE ID requests
Vulnerability tracking and security disclosure.
Policies
Security policies, enforcement, compliance, approvals, and scans.
Security glossary
Definitions for terms related to security features in GitLab.