13 ms·
GitLab 11.1 released with security dashboards and enhanced code search
- aw3c2 8y agoA month of nothing but performance tweaks and bugfixes would be great though.
- ggregoire 8y agoThey introduced "squash" and "modify commit message" on the last release. It worked 1 time on the 4 times I tried.
- victorwu 8y agoIf you could log a bug here with any details that would be great! https://gitlab.com/gitlab-org/gitlab-ce https://gitlab.com/gitlab-org/gitlab-ce Thanks! Edit: I wanted to clarify that if you’ve observed any undesirable behavior, we welcome you to log it and we will address it as soon as we can. I see how my original comment made it seem like we ship untested code. That’s not the case as Sid mentioned below. That being said, there might be specific edge cases or scenarios we have not captured in our tests. So problems do appear from time to time. So I wanted to invite anybody to log any problem so that we can reproduce it as soon as we can and get it fixed. Also as Sid mentioned, this feature was recently brought to Core so that more users now have access to it.
- hitekker 8y agoPlease stop using your customers as your Quality Control. I get Gitlab is going for "breadth over depth", but your company must ensure the features being promoted actually work. Shipping untested code does not build confidence.
- sytse 8y agoWe're not using our customers as quality control. Changes can be minimal but they have to meet our definition of done https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CONTRIBUTING.md#definition-of-done https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CONTRIBU... that includes tests. I assume the relevant product manager (Victor) hasn't heard this complain before but that doesn't show from his answer. This feature was open sourced in 11.0 https://about.gitlab.com/2018/06/22/gitlab-11-0-released/#squash-and-merge-in-gitlab-core-and-gitlabcom-free https://about.gitlab.com/2018/06/22/gitlab-11-0-released/#sq... after many people requested it https://gitlab.com/gitlab-org/gitlab-ce/issues/34591 https://gitlab.com/gitlab-org/gitlab-ce/issues/34591 but the code has been in use by users since GitLab 8.17 (Feb 22, 2017) https://gitlab.com/gitlab-org/gitlab-ee/merge_requests/1024 https://gitlab.com/gitlab-org/gitlab-ee/merge_requests/1024 so I think that is why Victor assumed this was a user specific problem.
- victorwu 8y agohitekker: See my edited comment above. We do not ship untested code. But any problems that users do find we definitely want them captured as soon as possible so that we can triage and fix.
- apple4ever 8y agoFixing merge conflicts is completely broken for me ever since they introduced it.
- sytse 8y agoWe have to balance shipping new features https://about.gitlab.com/handbook/ceo/#how-do-we-keep-shipping https://about.gitlab.com/handbook/ceo/#how-do-we-keep-shippi... with performance tweaks and bugfixes. If we would not have shipped new features and still did just just version control GitLab the company would not be viable. We're committed to shipping a single application for the whole DevOps lifecycle this year https://about.gitlab.com/2017/10/11/from-dev-to-devops/ https://about.gitlab.com/2017/10/11/from-dev-to-devops/ But there are multiple performance tweaks en bugfixes going out every month, including this one. The big performance tweak in this release is the merge request view refactor https://about.gitlab.com/2018/07/22/gitlab-11-1-released/#merge-request-comments-vuejs-refactor https://about.gitlab.com/2018/07/22/gitlab-11-1-released/#me... which makes loading merge requests much faster but there are 35 other performance improvements https://gitlab.com/groups/gitlab-org/-/merge_requests?scope=all&utf8=%E2%9C%93&state=merged&label_name%5B%5D=performance&milestone_title=11.1 https://gitlab.com/groups/gitlab-org/-/merge_requests?scope=... There were 141 bugs closed in this release https://gitlab.com/groups/gitlab-org/-/issues?scope=all&utf8=%E2%9C%93&state=closed&milestone_title=11.1&label_name[]=bug https://gitlab.com/groups/gitlab-org/-/issues?scope=all&utf8...
- aw3c2 8y agoThank you for this nice reply (and all the great work of course)!
- sytse 8y agoYou're welcome! :) Thanks for caring about GitLab. New features vs. bugfixes is a hard balance and feedback helps us to find it.
- mcny 8y agoCongrats on shipping! Sometimes new features appear straightforward but the implementation details can be complicated. For example, https://gitlab.com/gitlab-org/gitlab-ce/issues/18157 https://gitlab.com/gitlab-org/gitlab-ce/issues/18157 Just off the top of my head: How do you feel about CI/CD for gitlab? I mean in the sense of a publicly available unstable.gitlab.com where we warn users that everything will can get deleted at any time without notice? Maybe it is already possible?
- Promarged 8y agoOr cleaning up their work-in-progress, currently there are around 11307 issues open: https://gitlab.com/gitlab-org/gitlab-ce/issues https://gitlab.com/gitlab-org/gitlab-ce/issues
- sytse 8y agoAmong other things we use the issue tracker for feature proposals. So it is not a good proxy of work in progress.
- DanielDent 8y agoIt really really would. And it's a very good thing that their product allows you to self-host, because I have zero-confidence in their ability to properly operate infrastructure. But the attention to detail/quality on the product itself is lacking too. Don't get me wrong, I love gitlab as a product, but they really don't seem to care about working on anything that doesn't let them check another box on a marketing feature sheet. A selection of some issue I've filed... Only took around a year to fix: https://gitlab.com/gitlab-org/gitlab-ce/issues/25388 https://gitlab.com/gitlab-org/gitlab-ce/issues/25388 Then this issue lingered for about a year before being closed because a customer filed a similar issue a couple months after I did... that other issue is still open though, so maybe they'll get around to it eventually: https://gitlab.com/gitlab-org/gitlab-ce/issues/25535 https://gitlab.com/gitlab-org/gitlab-ce/issues/25535 Here's one from two years ago that's still open: https://gitlab.com/gitlab-org/gitlab-ce/issues/19846 https://gitlab.com/gitlab-org/gitlab-ce/issues/19846 It's possible that issue is actually fixed now. I don't know and I don't care anymore. Here another issue from 2 years ago: https://gitlab.com/gitlab-org/gitlab-ce/issues/19656 https://gitlab.com/gitlab-org/gitlab-ce/issues/19656 I filed that issue after a Gitlab person here on hacker news specifically invited feedback on UX/UI issues, and I had just spent a frustrating time trying to track down a runner. At some point I just stopped filing issues & started ignoring the issues I'd already filed. The times they decided to close issues because they'd been open a long time certainly didn't inspire me to waste any more time trying to help them improve the product. Closing & re-opening and re-tagging and doing everything but actually fixing the issue is not confidence inspiring. Gitlab is still a great product, but now when I run into things that might warrant opening an issue, I just find ways of dealing with them on my own.
- sytse 8y agoI wanted to give some context issue by issue. 1. We consider stopping an environment https://gitlab.com/gitlab-org/gitlab-ce/issues/25388 https://gitlab.com/gitlab-org/gitlab-ce/issues/25388 a new feature, not a bug. 2. Relative submodule links are planned for 11.3 https://gitlab.com/gitlab-org/gitlab-ce/issues/37356 https://gitlab.com/gitlab-org/gitlab-ce/issues/37356 3. Not showing a retry option to logged out users https://gitlab.com/gitlab-org/gitlab-ce/issues/19846 https://gitlab.com/gitlab-org/gitlab-ce/issues/19846 is a good improvement but since very few logged out users will see this message we don't consider it a bug. 4. Showing the original project next to the runner IDs makes a lot of sense. As you can see in the issue we are no longer closing feature proposals due to inactivity. If you find ways of dealing with above things on your own that involve modifying GitLab please consider contributing them back.
- some_account 8y agoThe most innovative source control product in the market just got even better. :)
- stefan_ 8y agoI just do not understand what they spend their time on. No ones giving out points for more checkmarks in a feature list, folks.
- spydum 8y agoHave you ever old software to an enterprise customer? Making your product look special by offering a bazillion features they will never use is surprisingly successful.
- deleted 8y ago[deleted]
- jsgo 8y agoIn our environment, a vendor would probably be better served to offer a no frills basics thing and then just sell customization support (or painless customization). You could probably check off every bulletpoint imaginable and then we would still have things that need customizing.
- SteveNuts 8y agoThat sounds like Atlassian's products to me. That can backfire after a few years of use when every page is customized to hell and back and no one knows how it works.
- simonturvey 8y agoOnly if you actually then invest some time in selling it. I've had radio silence from their sales team when requesting to purchase an self-hosted licence. The one thing I know about Microsoft (GitHub) - they _get_ enterprise sales.
- williamchia 8y agoHi Simon, I work at GitLab. Sorry for the radio silence. I do know we prioritize follow up based on company size & order size. If a smaller company requests a few licenses it can slip through the cracks. I've tracked down your record in our CRM and am escalating to our sales team so that you get a response.
- ModernMech 8y agoDoes anyone find it annoying that both Github and Gitlab have their own flavor of markdown which they both call GFM?
- simonturvey 8y agoI guess you didn't read the 11.1 release notes where they stated they were standardising on http://commonmark.org/ http://commonmark.org/ right?
- ModernMech 8y agoYeah, but they're still calling it "Gitlab Flavored Markdown". The release was just about how they're changing the renderer. This does nothing to reduce the confusion with the fact that there are still two "flavors" of Markdown called different things but referred to with the same acronym, but I guess now both rendered by the same backend? This makes no sense to me.
- zegerjan 8y agoThe additions GitLab has expand on Markdown. For example, if you comment with a string of hexidecimals larger than 8 characters, GitLab will try to link to the commit if it finds one. For issue 1, the reference pattern in #1. This is convenient in cases where you want to cross reference merge requests, snippets, and others, without copy pasting the links. The docs explain it better than I could: https://docs.gitlab.com/ce/user/markdown.html https://docs.gitlab.com/ce/user/markdown.html But in general, GitLab supports Markdown, with a few extensions.
- ksec 8y agoDoes anyone know if Gitlab is now on a monthly release schedule? Today is exactly one month after Gitlab 11.0 release. It seems Gitlab is finally on Rails 5.0, hopefully they move to Rails 5.2 soon. It seems the whole Rails Ecosystem, Shopify, Zendesk, Gitlab, AirBnb, Discourse is now catching up to the latest release.
- foepys 8y agoThey have been releasing new updates on the 22th of every month for over two years now.
- chriscool 8y agoYeah, GitLab has been on a monthly release schedule since October 2011: https://about.gitlab.com/2015/12/17/gitlab-release-process/ https://about.gitlab.com/2015/12/17/gitlab-release-process/
- deleted 8y ago[deleted]
- victorwu 8y agoYep, GitLab releases on the 22nd of everyone month. Here’s a list of releases. https://about.gitlab.com/releases/ https://about.gitlab.com/releases/
- blackst0ne 8y agoGitLab is not on rails 5.0 yet. But it's on its way.
- enjeru 8y agoAnyone using their OIDC integration should carefully read the release notes. Some form of migration action will be required.
- sytse 8y agoThis is about OpenID Connect, see https://about.gitlab.com/2018/07/22/gitlab-11-1-released/#store-user-id-in-openid-connect-sub-claim https://about.gitlab.com/2018/07/22/gitlab-11-1-released/#st...
- MurrayHill1980 8y agoIt would help if gitlab's web interface could make it possible to renew letsencrypt security certificates more easily than running local commands and cutting and pasting the certbot handshake string, then the SSL public and private keys. I have to do this every 3 months for the website for an open source project. Or if gitlab could sell ssh access to a VM host (for this purpose, not to use do any other significant computing) at reasonable cost.
- sytse 8y agoGitLab now uses Let's Encrypt for self-hosted installations. We plan to start using it for GitLab pages sites with custom domains and applications deployed with Auto DevOps. The issue for the latter is at https://gitlab.com/gitlab-org/gitlab-ce/issues/41355 https://gitlab.com/gitlab-org/gitlab-ce/issues/41355
- transitivebs 8y agoMy biggest issue with GitLab is that it's core 95% use case UX is just significantly weaker than GitHub's. This may seem subjective, and it certainly is to some extent, but I've used both platforms pretty extensively and I find GitHub's UX so much cleaner and more usable every time.
- blackst0ne 8y agoI use both GL and GH every day. And I find GH's UX is much weaker, e.g. it doesn't remember last used sort options on the issues page which is huge annoying. So this is subjective.
- marmaduke 8y agomaybe gitlab’s goal to integrate the whole of the software dev life cycle into a single UI isn’t the UX what you want. (Personally I find it a lifesaver)
- Scarbutt 8y agoI also find github's UI/UX much cleaner and easier to work with, gitlab tries to put too much stuff in one page and they are have low contrast.
- apple4ever 8y agoI actually find the opposite. Besides a self hosted option, the biggest reason I chose GL at work was because I found the UX so much better than GH. Like miles better. (Don't even get me started on the terribly named "Pull Request" which GL properly names as "Merge Request".
- Deimorz 8y agoAll my issues (on gitlab.com) now have an "Epic" field, but I can't find anywhere to actually create an epic. Am I missing it somewhere?
- romanr 8y agoThat’s an Enterprise feature, depends on what subscription you have.
- williamchia 8y agoNote, it's only a paid feature for private projects on GitLab.com. Public projects get all features of Gold for free: https://about.gitlab.com/open-source/ https://about.gitlab.com/open-source/
- victorwu 8y agoIf you have the Gold Plan (for a group) on GitLab.com, you will be able to use the Epics feature for that group. See [1]. If you have any other plan (including Free), you should not see that field (or at most you should see a dismissable upgrade UI). That doesn’t seem to be case currently. I’ve logged an issue to correct this. [2] [1] https://docs.gitlab.com/ee/user/group/epics/ https://docs.gitlab.com/ee/user/group/epics/ [2] https://gitlab.com/gitlab-org/gitlab-ce/issues/49484 https://gitlab.com/gitlab-org/gitlab-ce/issues/49484
- jerrac 8y agoMy favorite part of GitLab is the .gitlab-ci.yml and gitlab-runner workflow. My least favorite is how much RAM is required to run GitLab. You can't host your own on a $5 DigitalOcean vps. Does anyone know of any work being done on gitea/gogs, or other alternatives, that would support .gitlab-ci.yml and gitlab-runner? @gitlab It would be awesome if you would split out GitLab-CI into something you can host separately as a direct competitor to Jenkins. Or maybe a stripped down "lite" version that could be hosted on small vps's. I know that doesn't fit your overall vision, or really help your bottom line, but it would help a lot of individuals and small organizations that need to self host for some reason (as in, there's a reason they can't use GitLab.com).
- AlphaSite 8y agoisn't `.gitlab-ci.yml` just the same as a jenkins pipeline?
- jerrac 8y agoI haven't looked into Jenkin's in a couple years, so I'm not sure. My experience as the sysadmin of our Jenkin's server was decidedly negative. I was pretty happy when I was able to move to GitLab-CI instead of Jenkin's. It has it's issues, but at least I can upgrade it without breaking the entire instance....
- sytse 8y agoGitLab CI used to be a completely separate application. When we integrated both we learned of the emergent benefits of an integrated application https://about.gitlab.com/handbook/product/single-application/#emergent-benefits-of-a-single-application https://about.gitlab.com/handbook/product/single-application... and we want to keep those. I understand the need to have GitLab use less memory, I commented in https://news.ycombinator.com/item?id=17588073 https://news.ycombinator.com/item?id=17588073 about our plans. BTW If you want to use just GitLab CI and are a current GitHub customer you can do that https://about.gitlab.com/features/github/ https://about.gitlab.com/features/github/
- dirtylowprofile 8y ago
- kornish 8y agoHow does the code search compare to best-in-class search tools like SourceGraph? Looks like GitLab is still missing a lot of important utilities like informative tooltips, jump-to-definition, etc.
- sytse 8y agoGitLab code search is not on the same level as SourceGraph that has much more language dependent features.
- sqs 8y agoSourcegraph CEO here. :) Sourcegraph works really well with GitLab so you can search and browse code (with IDE-like code intelligence) across all of your GitLab EE/CE/.com repositories efficiently. See https://about.sourcegraph.com/docs/config/repositories#gitlab-configuration https://about.sourcegraph.com/docs/config/repositories#gitla... or just set it up with the one-command installation instructions on the homepage.
- XorNot 8y agoI'm about to switch my team to Gitlab hosted for one reason: it's the only CI product I can find which has any notion of allowing the feature-branch/shared-repo model to have secrets protected from regular committers during builds. Now if they could implement branch-specific secrets so I could manage ACLs amongst devs, senior devs, ops etc. then it would be near-perfect.
- iamjaredwalters 8y agoSecret variables are NOT output to Gitlab CI job logs... but if someone echos them, they WILL appear in the log. This may be obvious to some, but, I like to point it out nonetheless.
- benatkin 8y agoI think it would be a good feature to hide secrets from the log by searching for them and replacing them with something like [removed]. It would be best if it were done by a component that had the security locked down (maybe a process that you pipe it through) and it wouldn't prevent users from encrypting it to bypass the filter, but it would make it harder for misbehaving users to deny that they circumvented the security. It could also detect JSON stringified or base64'd secrets.
- DuskStar 8y agoAnd now I'll take the secret, base64 it, add a space between each character, reverse the order and base64 it again. And then toss it through a round of AES256 with my key, all before echoing it. Trying to prevent people from exfiltrating data by filtering the output stream is an impossible battle.
- benatkin 8y agoIt wouldn't stop outright, and I tried to communicate that I knew it wouldn't in my comment. It would make it so if someone got caught doing that, it would be harder for them to deny that they did it deliberately, and you could throw the book at them. As it is now, they could print it out and say that they were just debugging, or they could even think it was permissible to print it out.
- deleted 8y ago[deleted]
- prepend 8y agoThis is neat, but the pricing tiers are a bit extreme. I’d like to use static code analysis, but this is only available in platinum ($99/month/user [0]) or ultimate (unknown price - call sales). I currently use Core for free and going from $0 to $100k seems pretty steep for a fairly simple feature that Github has partially implemented in their free tier. [0] https://about.gitlab.com/pricing/#gitlab-com https://about.gitlab.com/pricing/#gitlab-com
- sytse 8y agoGood point. We're thinking about making security open source at the merge request level but charging for project, group, and instance level metrics. What would you think of that?
- prepend 8y agoThat’s better. I actually don’t necessarily mind paying or jumping through hoops, but it’s such a massive jump for what I see as a feature that I’ll likely have to buy a 3rd part product for much less than that. I’d like some way to use it manually as a low cost project and then pay for convenience. There’s a group in my org looking at MicroFocus at $1200/build seat.
- sytse 8y agoIf you want to use it manually consider looking at the .gitlab-ci.yml template included in GitLab EE. If you do it manually you'll probably have to send the results to an artifact to see them.
- dorian-graph 8y ago> external systems can no access all merge requests reliably Typo? Should it be "now"?
- kaushalmodi 8y agoI wished this update came with gitlab.com-wide project search. But looks like the "improved search" still didn't include that. Github-wide search is great! I wish Gitlab had something like that. That's one of the things that's stopping me from switching 100% to Gitlab. The site-wide search on GitHub allows me to explore code snippets, learn how someone else uses the "foo" syntax, see the trending repos in a given language, and so much more.