This page was machine-translated and may differ from the original. View original
GitLab Completes Integration of Fuzzing Solutions, Strengthening DevSecOps Capabilities
GitLab Acquires Peachtech-Fuzzit to Build Fuzzing Capabilities
Fuzz testing, unlike SAST or DAST, uses known CVEs.
Find security vulnerabilities specific to unidentified applications
There is growing interest in digital security. If security software developers can see the results of scanning such as fuzz testing before completing coding work, they can immediately identify what security flaws have occurred without having to figure out where the vulnerability occurred and what role it played.
GitLab announced on the 3rd that the integration work with Peach Tech and Fuzzit, which it acquired in June, has been completed.

Peach Tech is a security software company that provides protocol fuzz testing and DAST (Dynamic Application Security Testing) API testing, while Fuzzit is a continuous fuzz testing solution company that provides coverage-guided testing.
This integration gives GitLab users access to features like continuous fuzzing, coverage-guided fuzz testing, and web API fuzz testing, all while delivering results directly to developers as they iterate on their code.
Fuzz testing can complement other forms of application security testing, such as Static Application Security Testing (SAST) and DAST. While SAST and DAST find known vulnerabilities, fuzz testing finds application-specific vulnerabilities that are not identified by known Common Vulnerability Exposures (CVEs).
“Security can no longer be viewed as a separate step outside of the DevOps process,” said David DeSanto, GitLab’s director of security and protection phase products. “By integrating fuzzing technologies, GitLab makes it easy for development and security teams to merge coverage guidance and API fuzz testing techniques early in software development.”
“Developers can easily apply best DevSecOps practices and identify which security vulnerabilities are created in code commits,” he said. “This allows them to work closely with security officers to reduce security risks across the enterprise.”
All GitLab scanning, including fuzzing, DAST, SAST, dependency scanning, container scanning, secrets detection, and license compliance, is readily available within your CI pipeline, eliminating the need for complex APIs and plugins.
GitLab plans to accelerate innovation with its acquired fuzzing IP through an integrated approach, as well as add replay capabilities to DAST to easily reproduce how vulnerabilities arise and improve the fidelity of SAST capabilities based on fuzz testing results.
Specifically for fuzz testing, we plan to extend fuzz testing to cover additional use cases beyond web applications and APIs, or add configuration options for users who want to customize their fuzz testing.
Fuzz testing, unlike SAST or DAST, uses known CVEs.
Find security vulnerabilities specific to unidentified applications
There is growing interest in digital security. If security software developers can see the results of scanning such as fuzz testing before completing coding work, they can immediately identify what security flaws have occurred without having to figure out where the vulnerability occurred and what role it played.
GitLab announced on the 3rd that the integration work with Peach Tech and Fuzzit, which it acquired in June, has been completed.

▲ GitLab completes acquisition of Peach Tech and Fuzzit
We've secured fuzz testing technology [Image = GitLab]
We've secured fuzz testing technology [Image = GitLab]
Peach Tech is a security software company that provides protocol fuzz testing and DAST (Dynamic Application Security Testing) API testing, while Fuzzit is a continuous fuzz testing solution company that provides coverage-guided testing.
This integration gives GitLab users access to features like continuous fuzzing, coverage-guided fuzz testing, and web API fuzz testing, all while delivering results directly to developers as they iterate on their code.
Fuzz testing can complement other forms of application security testing, such as Static Application Security Testing (SAST) and DAST. While SAST and DAST find known vulnerabilities, fuzz testing finds application-specific vulnerabilities that are not identified by known Common Vulnerability Exposures (CVEs).
“Security can no longer be viewed as a separate step outside of the DevOps process,” said David DeSanto, GitLab’s director of security and protection phase products. “By integrating fuzzing technologies, GitLab makes it easy for development and security teams to merge coverage guidance and API fuzz testing techniques early in software development.”
“Developers can easily apply best DevSecOps practices and identify which security vulnerabilities are created in code commits,” he said. “This allows them to work closely with security officers to reduce security risks across the enterprise.”
All GitLab scanning, including fuzzing, DAST, SAST, dependency scanning, container scanning, secrets detection, and license compliance, is readily available within your CI pipeline, eliminating the need for complex APIs and plugins.
GitLab plans to accelerate innovation with its acquired fuzzing IP through an integrated approach, as well as add replay capabilities to DAST to easily reproduce how vulnerabilities arise and improve the fidelity of SAST capabilities based on fuzz testing results.
Specifically for fuzz testing, we plan to extend fuzz testing to cover additional use cases beyond web applications and APIs, or add configuration options for users who want to customize their fuzz testing.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














