🚨 GitLab Patch Releases: 18.4.1, 18.3.3, 18.2.7 Are Now Available 📅 Release Date: September 25, 2025 🛡️ Type: Security & Bug Fixes 📦 Applies to: GitLab Community Edition (CE) & Enterprise Edition (EE) GitLab has released three patch versions with critical security and stability improvements. These updates address multiple vulnerabilities, including: 🔐 High-Severity Security Fixes: CVE-2025-9642: XSS via Script Gadgets (CVSS 8.7) CVE-2025-10858: DoS via malicious JSON files (CVSS 7.5) CVE-2025-8014: Bypass of GraphQL query limits (CVSS 7.5) 🧵 Other notable vulnerabilities fixed: Information disclosure in virtual registry configs Privilege escalation from Developer role DoS via GraphQL blobSearch & string conversion methods Improper authorization and project ownership reassignment 📝 Bug Fixes Across All Versions: These releases also include dozens of backported fixes improving performance, user experience, and internal stability across GitLab CE/EE. 📌 Important Notes: No new DB migrations GitLab.com is already patched All self-managed instances should upgrade immediately GitLab Dedicated customers do not need to take action 🔄 Recommended Action: Upgrade your instance to 18.4.1, 18.3.3, or 18.2.7 depending on your version stream. 📖 Full release notes → GitLab Patch Blog 🔒 Read best practices → Securing GitLab Instances Source Link : https://lnkd.in/e_GmpN9J #GitLab #SecurityUpdate #CVE #DevSecOps #ApplicationSecurity #PatchNow #OpenSourceSecurity #BugFixes #GitLabEE #GitLabCE
GitLab Releases Patch Versions 18.4.1, 18.3.3, 18.2.7 with Security Fixes
More Relevant Posts
-
I just automated the entire software delivery lifecycle! Here's a glimpse of the end-to-end CI/CD pipeline I built: ✅ Code Commit triggers the magic. ✅Build & Unit Tests run automatically with GitHub Actions. ✅Security Scan (using Trivy) checks for vulnerabilities. ✅Containerize the app into a Docker image. ✅Deploy seamlessly to a Kubernetes cluster using ArgoCD. The result? Faster releases, fewer manual errors, and happy developers! 🎉 #DevOps #CICD #Automation #GitHubActions #Kubernetes #ArgoCD #CloudComputing #SoftwareEngineering
To view or add a comment, sign in
-
-
GitOps replaces imperative scripts with declarative desired state and automated reconciliation. Inventory current pipelines and pick a low‑risk service for the pilot. Design the repository structure first: environment‑specific desired‑state repos (or dirs), code owners, naming, and promotion paths. Then deploy your reconciler (ArgoCD/Flux) with SSO, RBAC, and audit logging enabled. Migrate iteratively. Convert manifests, enable health checks and sync policies, and route notifications to owning teams. Document incident procedures for pausing sync and rolling back so on‑call responders have confidence. Govern day‑to‑day through pull requests and reviews. When the pilot shows improved deployment frequency and reliability, scale to additional services. Use the checklist to get the structure, governance, and migration flow right: https://zurl.co/IcTkp
To view or add a comment, sign in
-
Ever wondered if your tests are really covering the critical parts of your code? Let’s break down what code coverage is, why it’s a must-have in DevSecOps, where it impacts quality, and which tools to use for different tech stacks. Dive into these slides to see how code coverage can make your software more robust and secure. #CodeCoverage #DevSecOps #QualityAssurance #SoftwareTesting #TestAutomation #CICD #CleanCode #SoftwareDevelopment
To view or add a comment, sign in
-
“The faster we move, the more risk we seem to create.” That’s what one enterprise engineering lead told us when their team realized that keeping their code quality platform secure and resilient had become a full-time job. In our latest story, Daniel from iTmethods shares how our Managed SonarQube Server solution helped the team shift focus from tool maintenance to delivering secure, compliant software faster. Read the full story: https://bit.ly/498IR1e #DevSecOps #SonarQube #DevOps #ManagedServices #iTmethods #CodeQuality #Security
To view or add a comment, sign in
-
12‑factor isn’t nostalgia—it’s a modernization guide. Treat config and secrets as first‑class citizens. Integrate a secrets manager, use GitOps overlays, and kill `.env` surprises. Build once, then promote artifacts across environments with provenance (SLSA, signatures). Standardize logs with correlation IDs so diagnosis crosses service boundaries. Stateless by default; be explicit when state is necessary. Document contracts and failure modes for backing services. Use health probes and readiness checks consistently in your platform. Keep dev/prod parity with ephemeral environments and drift detection. Review quarterly, score services, and turn findings into a remediation backlog. Pair upgrades with roadmap work so improvements ship without stalling product goals. Use the manual as your translation layer from principles to today’s stack.
To view or add a comment, sign in
-
Unlocking Performance Insights: Running k6 Load Tests Locally with Docker & Grafana... Performance testing doesn’t have to be complex! 🚀 I recently explored running k6 load tests locally using Docker and visualizing results with Grafana, and it completely streamlined the process. Here in the PDF, you will find the full process: - #k6 #LoadTesting #Docker #Grafana #PerformanceTesting #DevOps #Monitoring #QA #TestingTools
To view or add a comment, sign in
-
DevSecOps is transforming how modern development teams deliver secure, reliable applications. By integrating security early into the CI/CD process, teams can
To view or add a comment, sign in
-
🚀 GitLab 18.5 is here — and it’s bringing intelligence to every corner of DevSecOps! Our partner GitLab just dropped their latest release: “Intelligence that moves software development forward.” Here’s what’s new 👇 🔥 Highlights that stand out: 💬 GitLab Duo Chat — now everywhere in your workflow for instant AI help. 🧠 New AI Agents like the Security Analyst and Planner — triage vulnerabilities, prioritize backlogs, and generate updates automatically. 🛡️ Smarter security — Reachability Analysis for Java, Secret Validity Checks, and Diff-based SAST scanning. 🧩 Native integration with top AI dev tools (Claude, Gemini, Q Developer, and more). ⚙️ Duo Agent Platform (beta) for self-managed environments — bring AI on-prem with data sovereignty intact. 💡 GitLab 18.5 isn’t just another update — it’s a leap toward smarter, faster, and more secure software development. 👉 Dive into the full release here: https://lnkd.in/gUgQZvqC Which new feature are you most excited to try? 👇 #GitLab #DevSecOps #AIDrivenDevelopment #SoftwareEngineering #DeveloperExperience #Automation #CyberSecurity #Innovation
To view or add a comment, sign in
-
-
🚀 GitLab 18.5 is here — and it’s bringing intelligence to every corner of DevSecOps! Our partner GitLab just dropped their latest release: “Intelligence that moves software development forward.” Here’s what’s new 👇 🔥 Highlights that stand out: 💬 GitLab Duo Chat — now everywhere in your workflow for instant AI help. 🧠 New AI Agents like the Security Analyst and Planner — triage vulnerabilities, prioritize backlogs, and generate updates automatically. 🛡️ Smarter security — Reachability Analysis for Java, Secret Validity Checks, and Diff-based SAST scanning. 🧩 Native integration with top AI dev tools (Claude, Gemini, Q Developer, and more). ⚙️ Duo Agent Platform (beta) for self-managed environments — bring AI on-prem with data sovereignty intact. 💡 GitLab 18.5 isn’t just another update — it’s a leap toward smarter, faster, and more secure software development. 👉 Dive into the full release here: https://lnkd.in/euG4rAV6 Which new feature are you most excited to try? 👇 #GitLab #DevSecOps #AIDrivenDevelopment #SoftwareEngineering #DeveloperExperience #Automation #CyberSecurity #Innovation
To view or add a comment, sign in
-
-
🚀 GitLab 18.5 is here — and it’s bringing intelligence to every corner of DevSecOps! Our partner GitLab just dropped their latest release: “Intelligence that moves software development forward.” Here’s what’s new 👇 🔥 Highlights that stand out: 💬 GitLab Duo Chat — now everywhere in your workflow for instant AI help. 🧠 New AI Agents like the Security Analyst and Planner — triage vulnerabilities, prioritize backlogs, and generate updates automatically. 🛡️ Smarter security — Reachability Analysis for Java, Secret Validity Checks, and Diff-based SAST scanning. 🧩 Native integration with top AI dev tools (Claude, Gemini, Q Developer, and more). ⚙️ Duo Agent Platform (beta) for self-managed environments — bring AI on-prem with data sovereignty intact. 💡 GitLab 18.5 isn’t just another update — it’s a leap toward smarter, faster, and more secure software development. 👉 Dive into the full release here: https://lnkd.in/emkiN5s4 Which new feature are you most excited to try? 👇 #GitLab #DevSecOps #AIDrivenDevelopment #SoftwareEngineering #DeveloperExperience #Automation #CyberSecurity #Innovation
To view or add a comment, sign in
-