Browse articles from Security


Tutorial: Secure and optimize your Maven Repository in GitLab
Learn the best practices, advanced techniques, and upcoming features that improve the efficiency of your DevSecOps workflow.

Introducing compromised password detection for GitLab.com
GitLab is adding compromised password detection on June 19, 2025. After that date, users logging in with known compromised passwords will be warned. Here is what you need to know.

Our step-by-step guide to evaluating runtime security tools
Key learnings from the GitLab Security team’s runtime security tool evaluation on Kubernetes clusters and Linux servers using real-world attack simulations.

How to use GitLab's Custom Compliance Frameworks in your DevSecOps environment
Explore how new frameworks, along with more than 50 out-of-the-box controls, transform regulatory requirements from burdensome checkboxes to integrated, automated workflow components.
Introducing Custom Compliance Frameworks in GitLab
Reduce manual tracking, accelerate audit readiness, and enforce controls faster natively within GitLab DevSecOps workflows.

Enhance application security with GitLab + HackerOne
Learn about the GitLab + HackerOne partnership and how to easily implement an integration that improves your organization’s application security posture.

Secure and safe login and commits with GitLab + Yubico
Learn how GitLab and Yubico have partnered to strengthen software development security through robust authentication measures.
Find out which plan works best for your team
Learn about pricingLearn about what GitLab can do for your team
Talk to an expert