Story
Lyft Uses GitLab Security for Developer Security
Lyft, an industrials organization in the United States, uses GitLab Security from GitLab to support secure delivery for developers and AppSec.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Developers and AppSec work from the same GitLab Security record for developer security |
| Risk and compliance | Developer security can be reviewed without waiting on a personal export |
| Risk and compliance | Named workflow replaces ad hoc routing for developer security |
Story
Inside Lyft, secure delivery used to depend on whoever still had the latest file. That pattern is common in industrials groups working out of the United States. Developers and AppSec needed a system that would still make sense after the original project team moved on.
Lyft uses GitLab Security from GitLab as the working layer for developer security. GitLab is a DevSecOps platform that combines source control, CI/CD, security scanning, and planning in one application. The practical change is simple: secure delivery has a home, and reviews happen there instead of in a forwarded thread.
Nothing in this writeup invents a savings number. What Lyft gets from GitLab is a durable place to run secure delivery and a way for developers and AppSec to see the same developer security at the same time.