GitLab Security & compliance Code quality

Open SAST findings

Part of the GitLab scanner findings check · fix arrives as a guide

What it is

GitLab SAST reports open findings in the project's own source.

Why it matters

Unlike dependency findings, these are in code you control and can fix directly. They persist because the vulnerability report is a separate dashboard from the one people work in daily.

How to fix it

Work through the findings by severity, fixing or dismissing each with a reason. Adding the scan to the merge request pipeline puts new findings in front of the author instead of in a dashboard. The vulnerability report this reads is a GitLab Ultimate feature, and only holds data once the scanners have run in a pipeline.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.