GitLab Code quality Security & compliance

GitLab project posture

Visibility, lifecycle, and 2FA on your connected project.

Overview

Reads the live GitLab API for the project’s exposure and lifecycle signals: who can see the source, whether the owning group enforces two-factor authentication, and whether the project is still one you are maintaining.

What it looks for

  • Project visibility set to public unexpectedly
  • Owning group not enforcing two-factor authentication
  • Archived project still connected and scanned as production
  • Source branches kept after merge, accumulating as stale refs

Why it matters

A project set to public during a demo stays public. A group that does not require 2FA is a group where one reused password is enough to reach your source.

Rules in this check

How the fixes arrive

GuideChanges only you can make safely arrive as a step-by-step guide you can follow yourself or hand to your coding agent.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.