Open SAST findings
Part of the GitLab scanner findings check · fix arrives as a guide
What it is
GitLab SAST reports open findings in the project's own source.
Why it matters
Unlike dependency findings, these are in code you control and can fix directly. They persist because the vulnerability report is a separate dashboard from the one people work in daily.
How to fix it
Work through the findings by severity, fixing or dismissing each with a reason. Adding the scan to the merge request pipeline puts new findings in front of the author instead of in a dashboard. The vulnerability report this reads is a GitLab Ultimate feature, and only holds data once the scanners have run in a pipeline.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.