GitLab
Security & compliance
Code quality
Releases
GitLab scanner findings
GitLab’s own vulnerability report, pulled into your scan.
Overview
Reads the GitLab security dashboard — dependency scanning, SAST, and secret detection — through the connector and reports the open findings alongside the rest of your stack health. Requires GitLab Ultimate; stays silent on other tiers.
What it looks for
- Known-vulnerable dependencies from dependency scanning
- Open SAST findings
- Active leaked secrets from secret detection
Why it matters
GitLab already runs these scanners. What is usually missing is anyone reading the dashboard, and an active leaked-secret detection is not something to triage next sprint.
Rules in this check
| What it reports | Fix path |
|---|---|
| Known-vulnerable dependencies | Guide |
| Open SAST findings | Guide |
| Active leaked secrets | Guide |
How the fixes arrive
GuideChanges only you can make safely arrive as a step-by-step guide you can follow yourself or hand to your coding agent.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.