Application Security Testing, Composition Analysis
GitLab の Composition Analysis グループは、コンテナスキャン、依存関係スキャン、ライセンスコンプライアンスを行うソリューションの開発を担当しています。
Security Factory エンジニアリングステージは、顧客のコードにあるセキュリティ問題を発見し、説明し、 修正を支援するエンジンを所有します。これには、アナライザー、検出ルール、脆弱性管理機能、 およびそれらに情報を提供する調査が含まれます。
このステージは、旧 Application Security Testing ステージに Security Insights グループと Security Infrastructure グループを加え、FY27 の Sec 再編で設立されました。
| ロール | 担当者 |
|---|---|
| ステージリード | Maw Wildpaner(@maw、暫定) |
| Principal Engineer | Isaac Dawson(@idawson) |
| Principal Engineer | Lucas Charles(@theoretick) |
| Principal Engineer | Meir Benayoun(@mbenayoun) |
| グループ | Engineering Manager | Tech Lead | ラベル |
|---|---|---|---|
| Secret Detection | Amar Patel(@amarpatel) | Ahmed Hemdan(@ahmed.hemdan) | group::secret detection |
| Composition Analysis | Ethan Feller(@efeller) | Nick Ilieskou(@nilieskou) | group::composition analysis |
| Code Scanning | Ethan Feller(@efeller) | Yoric Teller(@yteller) | group::code scanning |
| Code Security | Ethan Feller(@efeller) | Philip Cunningham(@philipcunningham) | group::code security |
| AI Security | 未定 | Mher Tolpin(@mtolpin) | group::ai security |
| Vulnerability Management | AJ Biton(@ajbiton) | Lorenz van Herwaarden(@lorenzvanherwaarden) | group::vulnerability management |
| Agentic Security Flows | AJ Biton(@ajbiton) | Savas Vedova(@svedova) | group::agentic security flows |
| Threat Research | Daniel Abeles(@dabeles) | Dinesh Bolkensteyn(@dbolkensteyn) | group::threat research |
| Security Foundations | Ryan Wells(@ryaanwells) | Gregory Havenga(@ghavenga) | group::security foundations |
グループメンバー情報は Workday を情報源とし、 プロダクトカテゴリページで公開しています。
このステージの作業には、devops::security factory ステージラベルに加えて、担当グループの
group:: ラベルが付けられます。どちらもスコープ付きラベルであり、gitlab-org と
gitlab-com のトップレベルグループに存在します。
#sec-security-factory-eng:ステージのエンジニアリングチャンネル。各グループのチャンネルは、それぞれのグループページに記載されています。複数のチャンネル名変更が まだ進行中であり、 Sec 再編 Issue 2で追跡しています。
a1f3c26a)