Skip to main content

GitLab

The AISafe GitLab integration connects your GitLab account to AISafe. It provides source access for code audits and automated PR security review.

How it works​

AISafe connects to GitLab via OAuth. Authorizing the AISafe GitLab application gives AISafe read access to your repositories, so AISafe can clone source code for code audit assessments. The integration supports both GitLab.com (SaaS) and self-hosted GitLab instances.

Connecting GitLab​

  1. Navigate to Integrations in the AISafe dashboard.
  2. Click Connect GitLab. Only the organization owner sees this page; the connection it creates belongs to your AISafe organization, which has one source-code connection, and managers and above use it.
  3. GitLab redirects you to authorize AISafe. Choose which projects to grant access to.
  4. After authorization, your GitLab repositories appear in the Available repositories table.

Source access for code audits​

While you choose source files in a draft, AISafe reads repository paths and file sizes without downloading file contents. This applies to connected repositories and public GitLab URLs. Source archives are downloaded when you submit the draft for validation; connected repositories use your GitLab connection's OAuth token.

If GitLab cannot provide a file's size, the picker marks it as unknown. If a repository is too large to browse, upload an archive of the source files instead.

PR review​

GitLab repositories bound to a project support PR review. AISafe receives merge request webhooks, posts a review summary as a note on the merge request, and adds inline discussions on the flagged lines.

PR review on GitLab differs from GitHub in one way. On GitHub, AISafe creates a native check run. GitLab has no equivalent that every tier can use, so AISafe publishes a commit status instead. GitLab attaches a commit status as a job on the commit's pipeline and creates a pipeline with the source external when the commit has none. As a result, a project that runs no CI of its own will start to show pipelines that its team did not create. If you do not want this, turn Status check off in the project's PR review settings.