aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • DevOps

GitLab’s Fifth Annual Global DevSecOps Survey Reveals: 2020 Was Catalyst For DevOps Tool Adoption

  • aster.cloud
  • May 6, 2021
  • 5 minute read

GitLab Inc., the single application for the DevOps lifecycle, released the results of its fifth annual DevSecOps survey, uncovering how roles across software development teams have changed as DevOps teams mature. The survey of nearly 4,300 respondents from around the world found DevOps teams dramatically increased the pace of technology adoption which allowed them to take larger steps toward DevSecOps, increased release speeds and advanced automation.

“This year’s Global DevSecOps Survey shows that 2020 was a catalyst for DevOps maturation,” said Eric Johnson, CTO at GitLab. “Teams worldwide worked to streamline development cycles and deliver faster release time than ever before, all while adjusting to remote work and shifting priorities to meet the high demands of last year. We believe we will see improvements in testing as more teams adopt tools to automate the parts of DevSecOps that have continuously caused cycles to slow down.”


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

Based on the 2021 survey results, the COVID-19 pandemic enforced the broad adoption of remote work, which in turn energized teams to focus on embracing cutting edge DevOps technologies such as Kubernetes, machine learning/artificial intelligence (ML/AI) and cloud computing. In the past year, DevOps matured and fully arrived with these technology adoptions, but there are still roadblocks to navigate before achieving true DevSecOps.

 

DevOps Gets Automated and Ops Teams Reprioritize for 2021

Like last year, the 2021 report found that software testing and code review remained sticking points but how those challenges are handled is strikingly different. Amazingly 75% of respondents report their DevOps teams are either using or planning to use ML/AI for testing and code review, up 41% from 2020’s survey. This broad adoption of cutting edge technologies represents a larger shift in the industry towards integrating automation into their software development lifecycle. A majority (55%) of operations teams report their life cycles were either completely or mostly automated. For contrast, in 2020, just 8% of teams claimed full automation.

Read More  SpringOne 2020 Day 2: Explore The Next Frontier Of Dev-Centric Platforms

By integrating automation into their development cycles, DevOps teams’ members gain valuable time back to address other priorities. Operations teams, for example, have reshifted priorities to address the new software industry landscape shaped by the events of 2020. Fifty-six percent of operations professionals now report their first priority is managing cloud services (an increase from last year), no doubt a reflection of the mass migration to the cloud sparked by the pandemic. Additionally, operations teams report spending more time on compliance than they did in 2020, correlating to new compliance laws introduced last year like the California Privacy Rights Act (CPRA). Without adopting new technology to streamline development cycles, operation teams may likely have had a harder time reprioritizing to meet the new demands.

 

Releases are Faster Than Ever and Testing Remains a Sticking Point

Success in the software industry relies on release speed, and DevSecOps is the way to make it happen. This year, 84% of developers said they’re releasing code faster than ever before. This increase in release speed is due to the addition of tools like source code management and Continuous Integration and Continuous Delivery (CI/CD). Nearly 12% of respondents said adding a DevOps platform has sped up the process. Overall, 57% of respondents reported code is released twice as fast – a big increase from last year’s 35% – and 19% said code gets released 10 times faster.

Even with faster release times, security testing remains a sticking point for DevOps members. Over 42% of respondents felt it’s happening too late in the process, and nearly the same percentage said it was a struggle to unpack, process, and fix vulnerabilities. Almost 37% said tracking the status of the bug fixes was challenging, and 33% found remediation prioritization difficult. Like last year, these results indicate a reactive approach to security in the development process. It also indicates the importance of integrating DevSecOps in development cycles, because issues raised in testing that create bottlenecks could be caught and addressed earlier in development.

Read More  A Compliance Win: GitLab Successfully Completed SOC 2 Type II And SOC 3 Certifications

 

DevSecOps Matures but Security Ownership Remains a Pain Point

Continuing a trend the 2020 DevSecOps report indicated, developer roles continue to shift left, taking on more responsibility for what were traditionally operations- and security-related tasks. In 2021, more than 70% of security professionals report their teams have moved security considerations earlier into the development, or “shifted left” — an increase from last year’s 65%. Research indicates this broad increase in shifting left is due in part to an increase in developers conducting static and dynamic application security testing. Fifty-three percent of developers reported running static application security testing (SAST) scans (a 13% increase from last year) and 44% of developers reported running dynamic application security testing (DAST) scans (a 17% increase from last year).

Overall, this indicates a major step towards putting the “Sec” in DevSecOps — and the industry is seeing the benefits too. In fact, the report shows how far DevSecOps has come in the last year, with an unprecedented 72% of security professionals reporting their organizations’ security efforts were either “good” or “strong.” That’s a significant improvement from last year, when only 59% said the same thing. The largest year over year increase was in the “strong” category – last year only 19.95% of respondents considered their security posture in that light compared to nearly 33% in 2021.

While teams are showing signs of moving towards DevSecOps, research indicates organizations still struggle with determining who is in charge of security. Almost 31% reported they (security) were fully responsible for it, but almost 28% said everyone was responsible. This response is similar to last year’s, and underscores the need for clarity on this subject.

“While the industry has continued integrating security into development, and organizations are beginning to improve security overall, our research shows that a more clear delineation of responsibilities and adoption of new tools is required to completely shift security left,” said Johnathan Hunt, vice president of security at GitLab. “In the future, we hope to see security teams find more ways to lay out clear expectations for the other members of their organization, and continue to adopt innovative technologies for scanning and code reviews to improve speed and quality of development cycles.”

While greater strides toward implementing DevSecOps practices have been made this year than in years previous, there is more work to be done when it comes to organizing and coordinating responsibility between security, developer and operations teams. To access the full report, click here.

Read More  My Favorite Open Source Project Management Tools

Methodology

GitLab surveyed more than 4,294 software professionals worldwide from January to early March, 2021. The margin of error is 1% (assuming 27 million software professionals and 95 percent confidence level).

About GitLab

GitLab is the open DevOps platform built from the ground up as a single application for all stages of the DevOps lifecycle enabling Product, Development, QA, Security, and Operations teams to work concurrently on the same project. GitLab provides a single data store, one user interface, and one permission model across the DevOps lifecycle. This allows teams to significantly reduce cycle times through more efficient collaboration and enhanced focus.

Built on Open Source, GitLab works alongside its growing community, which is composed of thousands of developers and millions of users, to continuously deliver new DevOps innovations. GitLab has an estimated 30 million+ users (both Paid and Free) from startups to global enterprises, including Ticketmaster, Jaguar Land Rover, NASDAQ, Dish Network, and Comcast trust GitLab to deliver great software faster. All-remote since 2014, GitLab Inc. has more than 1,300 team members in approximately 68 countries.


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • DevOps Survey
  • DevSecOps
  • GitLab
You May Also Like
Users with laptops working with database. Data storage and organization, information access and management, big data protection concept. Vector isolated illustration.
View Post
  • Architecture
  • DevOps
  • Technology

What is application migration? Examples and best practices

  • August 18, 2025
View Post
  • DevOps
  • Engineering
  • Platforms

How To Fail At Platform Engineering

  • March 11, 2024
View Post
  • Computing
  • DevOps
  • Platforms

The IBM Approach To Reliable Quantum Computing

  • November 28, 2023
DevOps artifact management
View Post
  • Design
  • DevOps
  • Engineering

10 Awesome Benefits Of Artifact Management And Why You Need It

  • August 2, 2023
Automation | Gears
View Post
  • Automation
  • DevOps
  • Engineering

Automating CI/CD With GitHub Actions

  • June 13, 2023
View Post
  • DevOps
  • People

What’s The Future Of DevOps? You Tell Us. Take The 2023 Accelerate State Of DevOps Survey

  • June 2, 2023
View Post
  • Cloud-Native
  • DevOps
  • Software

7 Ways To Turn Developer Experience Into A Competitive Edge

  • May 10, 2023
View Post
  • DevOps
  • Programming
  • Software Engineering

PromptOps In application Delivery: Empowering Your Workflow with ChatGPT

  • April 30, 2023

Stay Connected!
LATEST
  • Data center 1
    Data Sovereignty in Spain. It’s Not Just About the Law, It’s About Efficiency
    • June 3, 2026
  • 2
    Ink vs Pixels. What you miss versus what you are actually missing.
    • June 1, 2026
  • 3
    Banks race to patch new cyber vulnerabilities, and other cybersecurity news
    • May 25, 2026
  • pope-leo-xiv-cq5dam-1500.844 4
    Pope Leo XIV to Publish First Encyclical on Artificial Intelligence and Human Dignity on 25 May
    • May 22, 2026
  • 5
    Portfolio to Clients, and is Strengthened by Ongoing Project Glasswing Work
    • May 20, 2026
  • reMarkable Paper Pure 6
    Everything The reMarkable Paper Pure Actually Does
    • May 14, 2026
  • 7
    Scaling cloud and AI: Microsoft Azure’s commitment to Europe’s digital future
    • May 11, 2026
  • reMarkable Paper Pure 8
    The Quiet Revolution You Did Not Know You Needed
    • May 9, 2026
  • spain-qNO3XMQILTA-unsplash 9
    When the World Feels Unstable, Spain Remains the Calm. Here’s How to Get There Safely.
    • May 2, 2026
  • 10
    Why The CLOUD Act And Geopolitics Are Forcing A Data Sovereignty Reckoning In Europe
    • May 2, 2026
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • Anthropic Institute 1
    Introducing The Anthropic Institute
    • March 11, 2026
  • Red Hat OpenShift 2
    Red Hat Further Drives Digital Sovereignty for the AI Era with Red Hat OpenShift on Google Cloud Dedicated
    • April 21, 2026
  • Illustration of data storage 3
    The Splinternet Comes for European Supply Chains Why Fragmentation Is Now a Boardroom Problem
    • April 20, 2026
  • 4
    “A lot of other cloud vendors have been let off the hook”: Oracle leans hard on one-size-fits-all appeal of OCI for enterprises
    • March 30, 2026
  • 5
    Why channel partners must design for tech sovereignty
    • April 7, 2026
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.