GitLab
Follow
Securing the software factory at machine speed
The software development landscape is rapidly evolving with the rise of abundant code, making trust the new scarce resource. Detection alone is insufficient for robust defense; security, governance, and guardrails must be integrated throughout the software development lifecycle. Leaders need continuous awareness of their attack surface, constrained execution, and rapid, machine-speed remediation from detection to verified fix. The economics of attacks are shifting, with AI models making it faster and cheaper for actors to discover and exploit existing weaknesses. This acceleration is evident in increasing CVEs and bug bounty reports at GitLab and across the industry. Traditional security models struggle as AI agents can chain low into high-severity findings. Therefore, an operating model change is necessary, embedding security controls within the execution path and implementing closed remediation loops. This approach creates a governed path across the entire software development lifecycle. Despite rising risks, generative AI can empower defenders by providing machine-speed discovery, prioritization, and remediation capabilities across code, infrastructure, and deployment paths. The build process is becoming more observable, with agent actions creating event streams that can be recorded and governed. This allows for a more robust security posture as model capabilities and commit volumes increase. A three-layered approach is proposed: proactive discovery of the attack surface, strengthening foundational security with continuous scanning and remediation, and protecting deployed software through ongoing monitoring and rapid fixes. Furthermore, addressing the "shadow software factory" is crucial, ensuring that code produced by agents is auditable and governed.