Lessons#

Seven end-to-end lessons that walk you through the entire GitLab DevSecOps workflow against this intentionally vulnerable application. Lessons build on each other — work through them in order.

#TitleDescription
1Configuring the Demo ApplicationImport the project and optionally deploy the application to a Kubernetes cluster
2Setting up Security Scanners and PoliciesConfigure built-in scanners, apply security configuration profiles, integrate a third-party scanner via SARIF, enable Secret Push Protection, and add policy guardrails
3Developer Security WorkflowsWalk through the developer experience: MR widgets, code flow, license compliance, injected jobs, and fixing in the Web IDE with Duo
4Overseeing Security PostureTriage with CVSS / EPSS / KEV / reachability, and view the vulnerability report, security inventory, SBOM, audit events, and continuous scanning
5GitLab Duo AI Security FeaturesUse Duo’s Security Analyst and Security Review agents, false positive detection, and agentic vulnerability resolution
6Custom Compliance FrameworksBundle scanners, policies, and audit evidence into named compliance frameworks (and templates) and apply them across projects
7Roles and PermissionsEnforce least privilege and separation of duties with default roles, the Security Manager role, and custom roles