GitLab
Security & compliance
Code quality
Project is publicly visible
Part of the GitLab project posture check · fix arrives as a guide
What it is
The project's visibility is set to public, so its source is readable without authentication.
Why it matters
Public visibility is often set during a demo or an import and never reverted. Anything in the repository — configuration, internal endpoints, historical credentials — is world-readable and indexable.
How to fix it
Set visibility to private or internal, then audit what was exposed while it was public and rotate any credential in the history. Assume anything public was fetched.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.