Back to integrations
    SCASASTTicketing & Messaging

    GitLab integration

    Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.

    Integration details

    Primary category

    Workflow & Collaboration

    Sync direction

    GitLab ↔ Konvu

    Findings are ingested from GitLab into Konvu. What Konvu writes back to GitLab depends on the integration.

    Status

    Available

    What is GitLab?

    GitLab is a DevOps platform with integrated SAST and SCA security scanners that run in CI/CD pipelines, plus issue tracking and merge request workflows.

    Why connect GitLab to Konvu

    • Determine which GitLab security pipeline failures warrant blocking merges versus accepting with documentation.
    • Reduce false positives from GitLab's bundled scanners by layering exploitability analysis and environment context.
    • Sync triage outcomes to GitLab Issues and vulnerability reports for unified team workflows.

    How it works

    1

    Scan

    GitLab produces findings from scans or assessments.

    2

    Ingest & enrich

    Konvu ingests those findings and enriches them with code, configuration, and deployment context.

    3

    Assess exploitability

    Konvu determines exploitability and recommended action with evidence attached.

    4

    Record decisions

    Konvu records each verdict with its evidence. What it can write back to GitLab depends on the integration.

    Quick setup

    Configure GitLab from the integrations list in Konvu.

    1. 1Go to /configuration/integrations in Konvu and choose GitLab.
    2. 2Authorize access and confirm the data sources you want to sync.
    3. 3Save the configuration to start syncing.

    Sync direction

    GitLab ↔ Konvu

    Findings are ingested from GitLab into Konvu. What Konvu writes back to GitLab depends on the integration.