GitFlic Developers Make Software Development as Secure as Possible
Vulnerability management is now fully under control.

The cybersecurity market is driving an ever-growing list of new requirements. Simply finding vulnerabilities in finished applications is no longer enough. Data protection must be built directly into the software development process, and that requires specialized tools.
Less Routine Work for Developers
Astra Group has announced a new version of GitFlic, a Russian DevOps platform for working with source code. It can be accessed through the cloud or deployed directly within a customer’s IT environment. In the latest release, the most significant changes affect the Security section. In practice, vulnerability management has been turned into a fully controlled process. This gives security teams a way to conduct review sessions that distinguish genuine, confirmed threats from false positives, while other team members can verify the results through a workflow similar to reviewing a merge request.
“Security has also been improved within the development process itself. A merge request now displays not the full list of findings, but only the vulnerabilities introduced or resolved by the specific change. This approach reduces the workload for developers and reviewers: the team can see the impact of its own code, make merge decisions faster and avoid spending time analyzing inherited findings, while defects are fixed at the earliest and least expensive stage,” representatives of Astra Group explain.

Track the Status of Every Software Version
Special attention has also been given to projects with long life cycles. For software with multiple supported versions, developers can create separate LTS branches. This makes it possible to track the status of the same vulnerabilities separately in each current build. The capability is particularly useful for vendors and enterprise customers that maintain several releases for different clients at the same time. Security teams can now see where a potential threat has already been eliminated and where additional work is still required.
The platform also now supports vulnerability tagging during a review session, speeding up the bulk analysis of findings by information security teams. The platform’s API has been expanded as well, adding REST API methods for deleting branches and methods for managing variables, as well as for assigning and removing the administrator role in self-hosted installations.

Keeping Pace With Global Trends
The importance of continuously updating GitFlic is difficult to overstate. Solutions designed to make the software development process as secure as possible are in demand not only in Russia but around the world. Russia is also developing its own tools, reducing reliance on foreign service providers. That makes life easier for developers and, ultimately, for ordinary people, who can benefit from more secure digital services.
GitFlic itself has evolved steadily over the past several years. In 2021, its developers completed beta testing and began developing the service as a Russian platform for working with source code. At the first stage, the product was focused primarily on repository storage and collaboration among developers. But the platform’s underlying concept was designed to support further expansion of its capabilities.

More Opportunities for Improvement
In 2023, ReSollut, the developer of GitFlic, became part of Astra Group. This gave the platform’s creators additional resources to improve the product. The integration proved to be a strategically important step as demand grew in subsequent years for tools that could incorporate quality and security controls directly into the development process. GitFlic’s creators were able to respond quickly to changing customer requirements.
The platform’s latest update further confirms that Russia’s software development market is moving from separate security tools toward comprehensive secure-development ecosystems. In the coming years, DevOps, AppSec and vulnerability management tools are expected to become increasingly integrated into unified platforms. For Russian developers, such solutions are becoming part of the infrastructure needed to maintain technological independence.









































