GitLab integration
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
Integration details
Primary category
Workflow & Collaboration
Sync direction
GitLab ↔ Konvu
Findings are ingested from GitLab into Konvu. What Konvu writes back to GitLab depends on the integration.
Status
Available
What is GitLab?
GitLab is a DevOps platform with integrated SAST and SCA security scanners that run in CI/CD pipelines, plus issue tracking and merge request workflows.
Why connect GitLab to Konvu
- Determine which GitLab security pipeline failures warrant blocking merges versus accepting with documentation.
- Reduce false positives from GitLab's bundled scanners by layering exploitability analysis and environment context.
- Sync triage outcomes to GitLab Issues and vulnerability reports for unified team workflows.
How it works
Scan
GitLab produces findings from scans or assessments.
Ingest & enrich
Konvu ingests those findings and enriches them with code, configuration, and deployment context.
Assess exploitability
Konvu determines exploitability and recommended action with evidence attached.
Record decisions
Konvu records each verdict with its evidence. What it can write back to GitLab depends on the integration.
Quick setup
Configure GitLab from the integrations list in Konvu.
- 1Go to /configuration/integrations in Konvu and choose GitLab.
- 2Authorize access and confirm the data sources you want to sync.
- 3Save the configuration to start syncing.
Sync direction
GitLab ↔ Konvu
Findings are ingested from GitLab into Konvu. What Konvu writes back to GitLab depends on the integration.
More integrations
View allGitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging
Arnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
Semgrep
Find out which Semgrep Supply Chain and Semgrep Code findings are exploitable, with the evidence behind each verdict.
- SAST
- SCA
Snyk
Find out which Snyk Open Source and Snyk Code findings are exploitable in your code, with the evidence behind each verdict.
- SCA
- SAST
- Container Security