Gitlab and Google Cloud Partner to Expand AI-Assisted Capabilities
googlecloudpresscorner.com
googlecloudpresscorner.com
AI sound cool but at this point I'm just expecting another half baked feature that checks boxes for executives to justify purchasing it.
I'm hopeful GitLab can turn it around, but at this point it feels like GitLab might be going the way of Jira.
Cheers for highlighting it!
[1] https://gitea.io
Anyone here have set up CI pipelines with Gitea? What was your experience like? Did you make any CI pipelines for Rust code doing things like checking cargo audit, and running cargo clippy, cargo fmt, etc? As well as CI pipelines to automate building and deployment?
I encounter this issue pretty often and it makes code review experience miserable. It's not blocking any work, but it is frustrating enough that for any new project I would try to avoid using Gitlab
The comment you're replying to has a link to an issue which includes a video and a test project.
https://gitlab.com/gitlab-org/gitlab/-/issues/350662#note_10...
> However, I can still reproduce it under certain conditions:
Separately, that's not much of a defense; inconsistent errors are still problems for users. Although, I suppose gitlab only fixing bugs that are 100% reproducible would explain a lot about their product.
Or core features such as actual git reliably working well. Yesterday all my pulls/pushes were slow - I timed one push at over 2 minutes!
Its unfortunate, but just fixing and making an existing product awesome has lower ROI than implementing good-enough features that your competitor has. It may sound stupid, but works business wise.
I'm also planning to improve my fitness by 10x from tomorrow. Using AI obviously! But today let me eat this pizza
98% of "SecOps" is utterly pointless boxchecking for ass-covering security certifications which waste immense amounts of time and enforce nothing meaningful. You could ABSOLUTELY 10x workflow efficiency there by plumbing the codebase for questions like:
"What are all the OSS libraries you use, and the licenses?"
"What's your test coverage?"
"Do you encrypt your passwords at rest?"
"Are your S3 buckets encrypted?"
instead of wasting developer time answering questionaires nobody reads.
Now excuse me because I have to finish my startup deck.
3DLLMDevSecOpsAIMLBigDataGPU
Right. I guess they'll also deal with Qualcomm for their strong commitment to openness, and Russia for its strong commitment to democracy.
GCP is genuinely quite open. Whereas AWS have the habit of creating proprietary services/making proprietary changes to open source stuff, a lot of what GCP does is based on open source and open standards, done in public, which they themselves push for. Some of their flagship services such as GKE and Cloud Run, their Service Mesh stuff, Cloud Build, etc. run on software open sourced by Google. Of course that's not always the case - BigQuery is fully proprietary, but it's much better than competitor clouds that release the bare minimum publicly to allow consumption, but don't actually make it possible to do the same thing as GCP on your own outside of their environment.
https://www.edweek.org/policy-politics/google-under-fire-for...
At this point Google is mainly known as online tracking company which loves to cancel projects, and they put a lot of effort into building this image to a point an observer can get the impression it's not an accident.
> How do you find a VM by IP address in Azure?
The point is that you probably don't need to/shouldn't. IPs are ephemeral, don't matter and can easily change, and shouldn't be used for anything like identity.
> The point is that you probably don't need to/shouldn't. IPs are ephemeral, don't matter and can easily change, and shouldn't be used for anything like identity.
Hi, the ip 1.2.3.4 seems to be one of our VMs, and it's relaying spam. Which vm is it?
AWS's UI varies dramatically by product, which is both part of the problem with it (lack of a coherent design language leads to confusion) and makes it hard to talk about AWS's UI. Everyone has a different opinion based on which subset of tools they use.
After 5 years of using gitlab, we’re planning to switch back to GitHub exactly because of copilot and the Polish of their other features. The only hesitation is the SSO tax.
I'm playing with self hosted Gitea and enjoying so far. Really easy to admin and supports oauth2. It doesn't have all GitLab DevSecOps stuff nor powerful project management features, but we never used those in the first place.
Finally, given current market risks, having less vendors is a huge win.
Ironically, CI/CD and issues being well integrated were the reasons we switched to GitLab in the first place. But since then we stopped using issues.
CoPilot X will help write PR descriptions, some code review, etc. All those things are on top of just hosting the repo.
0 - https://about.gitlab.com/blog/2023/05/03/gitlab-ai-assisted-...
One thing I will say is that I notice lately that GitLab seems to throw in the word DevSecOps everywhere these days almost as if an exec has ordered everyone to use it a minimum of 20 times a day. It feels like the marketing people are pushing some kind of buzzword quota.
Nonetheless, will keep an eye on these features before our renewal cycle in September.
There's this rule - it likely has a name, but I don't know what it is - the rule saying that two-syllable names are by far the easiest, most effortless and most likeable ones to deal with (and any popular name that isn't two-syllable will eventually get a diminutive that is).
DevOps is two-syllable, so it stuck. DevSecOps is three-syllable, so it sucks. That's on top of it looking like it was created by means of someone saying "oh oh and also security, and also security!".
Hah, yes. Do you have any idea how jarring it is to cheer for migrating issues from gitlab to jira? But it turns out that ugly but feature complete is better than easy to work with and missing key features (ever tried searching for something in issue comments? To say nothing of high level task tracking (management wants to know what blockers we have in this multi-step 23-item epic)).
Of course "Explain this vulnerability" does not exactly sound like a compelling use case. This press release is hot garbage that adds to Google's problems instead of solving them by being bland, vague, hand wavy, and unspecific.
I think MS has a the vastly superior play here with e.g. co-pilot, partner ships with openai, and a lot of people already using gpt 4 powered plugins in their IDEs.
The right level of ambition for Google & Gitlab would be "Create a pull request to address this vulnerability" or how about "Review this pull request". Gpt 4 can do code reviews with the codeGpt plugins for vs code and intellij. And it actually finds stuff when you do that.
Or they can just wait for MS to roll that out with Github. I have no inside information as to whether they are planning any such thing. But it's an obvious move and they have a lot of the pieces needed for doing a decent effort for that. Including AI that is more than a press release, actually works, and is being used productively by real developers already.
Why does every press release from Google read like "The dog ate my homework. Again.", lately?
I have added your suggestion with MR/PR to remediate security vulnerabilities to the feedback issue [0] for the explain this vulnerability feature. The issue is linked from the blog post that provides more details [1].
[0] https://gitlab.com/gitlab-org/gitlab/-/issues/407295#note_13...
[1] https://about.gitlab.com/blog/2023/05/02/explain-this-vulner...
It looks like they're picking their suitor now. Google could certainly take a page from the Nadella playbook and use them to bolster their third place cloud offerings. GCP needs an ecosystem of developer tools to give it a shot in the arm.
I predict that the same thing is ultimately going to happen with HuggingFace and the smaller clones (Replicate, etc.) They'll pick a tech giant to partner with, accept a large investment, and eventually look into an acquisition.
Didn't Replit just partner with Google, too?
Who gets bought by Amazon?
When Microsoft bought Github, they bought a platform. GitLab however, is just software, as gitlab.com is absolutely tiny compared to github.
Bug fixes, UX improvements and performance improvements are added to the monthly release blog post, for example GitLab 15.11 [1] - in case you want to follow these updates more closely.
[0] https://about.gitlab.com/direction/#fiscal-year-guiding-prin...
[1] https://about.gitlab.com/releases/2023/04/22/gitlab-15-11-re...
How about GitLab fix the most elemental mistakes they have made with the k8s operator for GitLab runner instead of... whatever the hell this is?
The more general (and in some sense gratuitous and unnecessary) risk is the carte-blanche of big tech to pursue any and all business models that are digitally based (e.g. adtech) in any combination they see fit.
Creating and enforcing clear rules about who does what with what responsibilities and liabilities etc would help explore that exciting but also very risky AI enabled "next phase" of IT without constantly second guessing what is really going on and what disasters it might be stoking...
Pun intended?
With all the domains in the world, they pick one that almost looks fake. Why not presscorner.google.com? (Or why not their TLD…)
Anyways, I look forward to some new improvements in Gitlab. Seems a little vague on the details, but I think some different flavors of LLMs should prove interesting. Seems likely it’d spit out different results than what OpenAI might give you.
Might indicate that Gitlab is going the direction of getting swallowed by Google though. Feels like these tech companies are playing Katamari and swallowing up everything to make these massive vertical stacks.
Or, you know, just use subdomains which has existed since forever...
There's no way to exclude certain subdomains, so once you've decided to share a cookie between subdomains you have to use a new domain if you want to exclude a site from sharing.
I think Google should fix this. The alternative is endless domain sprawl, for all time.
However strange that they didn't use withgoogle.com which IIRC is a commonly used separate domain for this type of thing.
Partnering with the incomprehensibly byzantine andcomplacent architect of the SEOpocalypse AND "late-to-the-ai-party" Google does not give faith that the solution will be more performant or private than Github's copilot.
This is just another in a series of terrible blunders in the last year that has wiped out any goodwill I had towards gitlab. WTF happened, did they get a new CEO or something?
At that point there are not anymore good reasons to favor Gitlab against GitHub regarding the path they are following.
It took a lot of effort to write this with a straight face. Ultimately, I failed.
[1] https://about.gitlab.com/blog/2017/02/01/gitlab-dot-com-data...
Assuming that nothing has changed or was learnt since that incident is a pretty uncharitable reading.
They need to earn their trust like everyone else.
Losing data is a big failure. I can see why folks would remember it.
(Was looking at getting off github due to this being done by Microsoft.)
Needs source. Neither Github, Gitlab, AWS, Azure, or GCP legally trains anything on enterprise codebase. If they do, it would be illegal.