GitLab Security & compliance Code quality

Project is publicly visible

Part of the GitLab project posture check · fix arrives as a guide

What it is

The project's visibility is set to public, so its source is readable without authentication.

Why it matters

Public visibility is often set during a demo or an import and never reverted. Anything in the repository — configuration, internal endpoints, historical credentials — is world-readable and indexable.

How to fix it

Set visibility to private or internal, then audit what was exposed while it was public and rotate any credential in the history. Assume anything public was fetched.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.