GitLab
Code quality
Security & compliance
GitLab project posture
Visibility, lifecycle, and 2FA on your connected project.
Overview
Reads the live GitLab API for the project’s exposure and lifecycle signals: who can see the source, whether the owning group enforces two-factor authentication, and whether the project is still one you are maintaining.
What it looks for
- Project visibility set to public unexpectedly
- Owning group not enforcing two-factor authentication
- Archived project still connected and scanned as production
- Source branches kept after merge, accumulating as stale refs
Why it matters
A project set to public during a demo stays public. A group that does not require 2FA is a group where one reused password is enough to reach your source.
Rules in this check
| What it reports | Fix path |
|---|---|
| Connected project is archived | Guide |
| Project is publicly visible | Guide |
| Source branches kept after merge | Guide |
| Group does not require two-factor authentication | Guide |
How the fixes arrive
GuideChanges only you can make safely arrive as a step-by-step guide you can follow yourself or hand to your coding agent.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.