By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: GitLab Introduces Advanced Vulnerability Tracking to Tackle Code Volatility and Double Reporting
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > GitLab Introduces Advanced Vulnerability Tracking to Tackle Code Volatility and Double Reporting
News

GitLab Introduces Advanced Vulnerability Tracking to Tackle Code Volatility and Double Reporting

News Room
Last updated: 2025/03/01 at 1:28 AM
News Room Published 1 March 2025
Share
SHARE

GitLab has introduced a new feature that addresses two significant challenges in vulnerability management: code volatility and double reporting. Code volatility refers to the frequent changes in codebases that can reintroduce previously resolved vulnerabilities, while double reporting occurs when multiple security tools identify the same vulnerability. This new feature integrates advanced tracking mechanisms to tackle these issues, enhancing the accuracy and efficiency of vulnerability detection and management.

Julian Thome, Staff Backend Engineer at GitLab summarised the announcement in a blog post. Highlighting the challenges of tracking vulnerabilities in dynamic codebases and heterogeneous environments, Thome mentioned that this new feature is particularly useful for teams practicing DevSecOps.

In modern software development, DevSecOps integrates security into the development lifecycle, enabling teams to deliver features quickly while maintaining security standards. However, the dynamic nature of CI/CD pipelines and the use of multiple Static Application Security Testing (SAST) tools create two significant challenges. The first is code volatility, where frequent changes in codebases can reintroduce previously resolved vulnerabilities. The second is double reporting, where multiple tools report the same vulnerability, leading to duplication and inefficiency. These challenges make vulnerability management difficult for developers and security teams to identify unique issues and prioritize fixes effectively.

GitLab’s Advanced Vulnerability Tracking is designed to address these challenges by improving the accuracy and efficiency of vulnerability identification. The feature uses contextual information from generated syntax trees to scope vulnerabilities more precisely.

Traditional methods often rely on <file, line number> pairs to identify vulnerabilities. The new feature utilizes a method called “location fingerprinting,” which generates identifiers for vulnerabilities that are less fragile across code changes compared to traditional tracking methods.

A study conducted by GitLab demonstrated that its Advanced Vulnerability Tracking method is 30% more effective than traditional line-based tracking. The study also found that the benefits of this approach increase over time.

We saw an interesting conversation on Reddit about Centralized Vulnerability Management tools. The original poster invited suggestions for centralised vulnerability management tools from the tech community. The responses on the post included tools such as Qualsys, Tenable, Vanta, Plextrac, etc.

About narrowing down the vulnerability management tool, one of the Reddit users, Beneficial_West_7821, gave an insightful response,

…I highly recommend running a technical PoV and making sure you pay attention to things like compatibility in practise with your security tool landscape, as well as aggregation, de-duplication, configurability, dashboarding, reporting etc.


There is a very wide range of capability and maturity in the market, and performance can vary significantly (for example in ingestion and processing, as well as in responsiveness of the UI).

The findings from the study related to Advanced Vulnerability Tracking method will be presented at the 47th International Conference on Software Engineering (ICSE) 2025 in the Software Engineering in Practice Track. The preprint of the study is named “A Scalable, Effective, and Simple Vulnerability Tracking Approach for Heterogeneous SAST Setups Based on Scope+Offset,” authored by Lucas Charles, Jason Leasure, and Hua Yan.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Baidu terminates $3.6 billion deal to acquire YY Live · TechNode
Next Article How to Manage Multiple Social Media Accounts |
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Alibaba to provide wholesale power to Mongolian consumers in latest expansion · TechNode
Computing
Zara Tindall opens up about ‘struggles’ in Royal Family and how they cope
News
How innocent people could be jailed because of ChatGPT and leave criminals free
News
Xiaomi appoints two female senior executives simultaneously for the first time · TechNode
Computing

You Might also Like

News

Zara Tindall opens up about ‘struggles’ in Royal Family and how they cope

2 Min Read
News

How innocent people could be jailed because of ChatGPT and leave criminals free

12 Min Read
News

Elizabeth Holmes’ partner reportedly fundraising for new blood-testing startup | News

1 Min Read
News

Today's NYT Wordle Hints, Answer and Help for May 11, #1422 – CNET

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?