GitLab Security & compliance Code quality Releases

GitLab scanner findings

GitLab’s own vulnerability report, pulled into your scan.

Overview

Reads the GitLab security dashboard — dependency scanning, SAST, and secret detection — through the connector and reports the open findings alongside the rest of your stack health. Requires GitLab Ultimate; stays silent on other tiers.

What it looks for

  • Known-vulnerable dependencies from dependency scanning
  • Open SAST findings
  • Active leaked secrets from secret detection

Why it matters

GitLab already runs these scanners. What is usually missing is anyone reading the dashboard, and an active leaked-secret detection is not something to triage next sprint.

Rules in this check

What it reportsFix path
Known-vulnerable dependencies Guide
Open SAST findings Guide
Active leaked secrets Guide

How the fixes arrive

GuideChanges only you can make safely arrive as a step-by-step guide you can follow yourself or hand to your coding agent.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.