惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
L
LangChain Blog
博客园_首页
量子位
Stack Overflow Blog
Stack Overflow Blog
F
Fortinet All Blogs
S
Secure Thoughts
P
Privacy & Cybersecurity Law Blog
H
Help Net Security
T
Threatpost
N
Netflix TechBlog - Medium
Cyberwarzone
Cyberwarzone
P
Proofpoint News Feed
C
Cisco Blogs
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
MyScale Blog
MyScale Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
I
InfoQ
Cisco Talos Blog
Cisco Talos Blog
A
Arctic Wolf
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
CERT Recently Published Vulnerability Notes
U
Unit 42
博客园 - 三生石上(FineUI控件)
Recent Commits to openclaw:main
Recent Commits to openclaw:main
C
CXSECURITY Database RSS Feed - CXSecurity.com
Security Latest
Security Latest
WordPress大学
WordPress大学
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
Docker
C
Check Point Blog
TaoSecurity Blog
TaoSecurity Blog
Project Zero
Project Zero
www.infosecurity-magazine.com
www.infosecurity-magazine.com
SecWiki News
SecWiki News
F
Full Disclosure
S
Security @ Cisco Blogs
T
Tor Project blog
V
V2EX
Y
Y Combinator Blog
S
SegmentFault 最新的问题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
GbyAI
GbyAI
B
Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
V
Visual Studio Blog
酷 壳 – CoolShell
酷 壳 – CoolShell

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
GitLab CI Security Scanning — Dependency Vulnerability Detection Setup
Vulert · 2026-06-20 · via DEV Community

A GitLab pipeline can build, test, and deploy successfully while still shipping a vulnerable package. Passing CI does not always mean the release is safe. It only means the checks you configured passed.

That is why GitLab CI security scanning matters. Dependency scanning, secret detection, and package audits help teams catch vulnerable open source components before they reach production. GitLab Ultimate includes built-in security features, but Free and Premium users can still build strong pipelines with open source tools.

GitLab’s Built-In Security Features — What’s Available on Which Tier

GitLab security scanning includes several features across application security and pipeline security. The availability depends on your GitLab tier and deployment model. GitLab Ultimate users get the strongest built-in experience, including integrated dependency scanning results, vulnerability reports, merge request widgets, and security dashboards.

Free and Premium users can still run security tools inside GitLab CI. The difference is usually where the results appear and how deeply GitLab integrates them into the UI. Open source scanners can publish artifacts, fail pipelines, and generate reports, but some GitLab-native security dashboards and widgets require Ultimate.

Feature Free Premium Ultimate
CI/CD pipelines Yes Yes Yes
Built-in dependency scanning No No Yes
SAST templates Limited by tier and configuration Limited by tier and configuration Yes
Security dashboard No No Yes
Merge request security widgets No or limited No or limited Yes
Open source scanners in CI Yes Yes Yes

Tip: If you are not on GitLab Ultimate, do not skip security scanning. Use Trivy, OWASP Dependency-Check, npm audit, pip-audit, composer audit, cargo audit, or gitleaks inside your pipeline.

Setting Up Built-In Dependency Scanning GitLab Ultimate

GitLab dependency scanning identifies known vulnerabilities in project dependencies, including direct, development, runtime, and transitive packages where supported. For Ultimate users, GitLab provides CI/CD templates that make setup simple.

Add the dependency scanning template to your .gitlab-ci.yml file:

include:
  - template: Jobs/Dependency-Scanning.gitlab-ci.yml

A minimal pipeline can look like this:

stages:
  - test
  - security

include:
  - template: Jobs/Dependency-Scanning.gitlab-ci.yml

GitLab runs the dependency scanning analyzer during the pipeline and publishes results as security data. In supported projects, results can appear in the merge request security widget, pipeline security tab, vulnerability report, security dashboard, dependency list, and dependency scanning report artifact.

The exact package coverage depends on the analyzer method and supported ecosystems. For modern dependency scanning, always scan resolved dependency files where possible, such as package-lock.json, yarn.lock, composer.lock, poetry.lock, Pipfile.lock, go.sum, Gemfile.lock, and similar lock files.

Warning: Scanning only top-level manifests can miss transitive dependency risk. Lock files and SBOMs give scanners a clearer view of what your application actually installs.

Open Source Alternatives for GitLab Free and Premium

GitLab Free and Premium users can run dependency scanners directly as CI jobs. This is often enough to fail dangerous builds, upload reports, and create a basic security workflow. You may not get the same GitLab-native dashboard experience, but you still get pipeline protection.

The best open source setup depends on your stack. Trivy is a strong general scanner for many teams. OWASP Dependency-Check is useful for broad dependency scanning and report artifacts. Package manager audits are simple and language-specific.

Trivy in GitLab CI

Trivy can scan a repository filesystem for dependency vulnerabilities. It supports many ecosystems and works well in GitLab CI because it can run inside a container image and fail pipelines based on severity.

stages:
  - security

trivy_dependency_scan:
  stage: security
  image:
    name: aquasec/trivy:latest
    entrypoint: [""]
  script:
    - trivy fs --severity HIGH,CRITICAL --exit-code 1 --ignore-unfixed .
  allow_failure: false

This job scans the repository and fails the pipeline if Trivy finds high or critical vulnerabilities. For a softer rollout, set allow_failure: true first, fix the existing backlog, then make the job blocking.

You can also publish the scan output as an artifact:

trivy_report:
  stage: security
  image:
    name: aquasec/trivy:latest
    entrypoint: [""]
  script:
    - trivy fs --format json --output trivy-report.json .
  artifacts:
    when: always
    paths:
      - trivy-report.json
    expire_in: 7 days

OWASP Dependency-Check

OWASP Dependency-Check detects publicly disclosed vulnerabilities in project dependencies and can generate HTML, JSON, XML, or other reports depending on configuration. It is useful when you want a portable report artifact from GitLab CI.

stages:
  - security

dependency_check:
  stage: security
  image:
    name: owasp/dependency-check:latest
    entrypoint: [""]
  script:
    - mkdir -p dependency-check-report
    - /usr/share/dependency-check/bin/dependency-check.sh
      --project "gitlab-project"
      --scan .
      --format "HTML"
      --out dependency-check-report
      --failOnCVSS 8
  artifacts:
    when: always
    paths:
      - dependency-check-report
    expire_in: 7 days
  allow_failure: false

The --failOnCVSS 8 flag makes the pipeline fail when findings meet or exceed that threshold. Teams with a large backlog may start at 9 or 10, then lower the threshold after cleanup.

Language-Specific Package Manager Audits

Package manager audits are quick to add and easy for developers to understand. They are not a full replacement for multi-ecosystem SCA, but they provide useful coverage for specific stacks.

For Node.js projects:

npm_audit:
  stage: security
  image: node:20
  script:
    - npm ci
    - npm audit --audit-level=critical
  rules:
    - exists:
        - package-lock.json

For Python projects:

pip_audit:
  stage: security
  image: python:3.12
  script:
    - pip install pip-audit
    - pip-audit -r requirements.txt
  rules:
    - exists:
        - requirements.txt

For PHP Composer projects:

composer_audit:
  stage: security
  image: composer:latest
  script:
    - composer install --no-interaction --no-progress
    - composer audit
  rules:
    - exists:
        - composer.lock

For Rust projects:

cargo_audit:
  stage: security
  image: rust:latest
  script:
    - cargo install cargo-audit
    - cargo audit
  rules:
    - exists:
        - Cargo.lock

These jobs can run together in one security stage. Use rules: exists so jobs only run when the relevant files exist.

Secrets Detection in GitLab CI

Secret detection finds credentials committed to the repository. This includes API keys, cloud tokens, private keys, database passwords, OAuth secrets, webhooks, and other sensitive values. A leaked secret can create immediate risk even if the code itself is secure.

GitLab provides a secret detection template. In projects where the feature is available, you can include it like this:

include:
  - template: Jobs/Secret-Detection.gitlab-ci.yml

For teams using Free or Premium without the built-in workflow they need, gitleaks is a practical alternative:

gitleaks:
  stage: security
  image:
    name: zricethezav/gitleaks:latest
    entrypoint: [""]
  script:
    - gitleaks detect --source . --report-format json --report-path gitleaks-report.json
  artifacts:
    when: always
    paths:
      - gitleaks-report.json
    expire_in: 7 days
  allow_failure: false

If secret scanning finds a real credential, rotate it immediately. Removing the string from the latest commit is not enough because the secret may still exist in Git history, CI logs, forks, or copied environments.

Scheduling Nightly Security Scans

Pull request scans only run when code changes. A dependency can become vulnerable tomorrow even if your repository does not change. That is why scheduled scans are important for GitLab CI security scanning.

GitLab supports pipeline schedules through the UI. Go to Build > Pipeline schedules, create a schedule, choose the target branch, and set the cron timing. A nightly dependency scan is a good default for production applications.

You can keep the CI file simple and let the GitLab schedule trigger the same jobs:

workflow:
  rules:
    - if: $CI_PIPELINE_SOURCE == "merge_request_event"
    - if: $CI_PIPELINE_SOURCE == "push"
    - if: $CI_PIPELINE_SOURCE == "schedule"

For scheduled-only security jobs, add rules like this:

nightly_trivy_scan:
  stage: security
  image:
    name: aquasec/trivy:latest
    entrypoint: [""]
  script:
    - trivy fs --severity HIGH,CRITICAL --exit-code 1 .
  rules:
    - if: $CI_PIPELINE_SOURCE == "schedule"

Security Results in Merge Request Widgets

Merge request security widgets help developers see security findings before merge. In GitLab Ultimate, supported security scanners can publish report artifacts that GitLab displays in merge requests, the pipeline security tab, the security dashboard, the project vulnerability report, and the dependency list.

For GitLab-native dependency scanning reports, the artifact type is dependency_scanning. This report format is meant for GitLab security ingestion, not just a downloadable file.

artifacts:
  reports:
    dependency_scanning: gl-dependency-scanning-report.json
  paths:
    - gl-dependency-scanning-report.json
  when: always

For Free and Premium workflows, you can still upload HTML, JSON, or text reports as normal artifacts. Developers can open the report from the pipeline page, even if it does not appear in the GitLab security dashboard.

The best policy is to make critical and high findings visible in merge requests, fail the pipeline only for serious issues, and create tickets for lower-risk findings. This keeps the security signal useful instead of turning every merge request into a noisy blocker.

Continuous Monitoring Beyond Pipeline Scans

CI/CD scans are valuable, but they run only when pipelines run. A new CVE can be disclosed between commits, between release cycles, or during a weekend. If your only protection is a pipeline scan, you may not know about the vulnerability until the next push or scheduled job.

Vulert complements GitLab CI by monitoring open source dependencies continuously. It analyzes manifest files and SBOMs against a database of 458,000+ known CVEs and alerts teams within hours when new CVEs affect their packages.

Vulert supports files such as package-lock.json, yarn.lock, pom.xml, build.gradle, requirements.txt, Pipfile.lock, poetry.lock, composer.lock, go.sum, Gemfile.lock, Cargo.lock, pubspec.lock, mix.lock, *.csproj, packages.lock.json, and SPDX/CycloneDX SBOMs.

It also provides fix guidance, exact fixed versions, exact CLI commands where available, CVSS details, Jira ticket creation, vulnerability history, and dependency health grouping. That makes GitLab vulnerability scanning more actionable because developers get the package, version, CVE, and fix path together.

Example Complete GitLab CI Security Pipeline

The following example combines dependency scanning with Trivy, npm audit for Node.js projects, gitleaks secret detection, artifacts, and schedule support.

stages:
  - test
  - security

workflow:
  rules:
    - if: $CI_PIPELINE_SOURCE == "merge_request_event"
    - if: $CI_PIPELINE_SOURCE == "push"
    - if: $CI_PIPELINE_SOURCE == "schedule"

trivy_dependency_scan:
  stage: security
  image:
    name: aquasec/trivy:latest
    entrypoint: [""]
  script:
    - trivy fs --format json --output trivy-report.json .
    - trivy fs --severity HIGH,CRITICAL --exit-code 1 --ignore-unfixed .
  artifacts:
    when: always
    paths:
      - trivy-report.json
    expire_in: 7 days

npm_audit:
  stage: security
  image: node:20
  script:
    - npm ci
    - npm audit --audit-level=critical
  rules:
    - exists:
        - package-lock.json

gitleaks:
  stage: security
  image:
    name: zricethezav/gitleaks:latest
    entrypoint: [""]
  script:
    - gitleaks detect --source . --report-format json --report-path gitleaks-report.json
  artifacts:
    when: always
    paths:
      - gitleaks-report.json
    expire_in: 7 days
  allow_failure: false

This is a practical starting point. Add Python, Composer, Maven, Go, Rust, or .NET jobs depending on your repository. Keep the security stage small at first, then expand coverage after the team fixes existing issues.

Key Takeaways

  • GitLab Ultimate includes built-in dependency scanning and deeper security dashboard integration.
  • GitLab Free and Premium users can still run strong open source security scans inside GitLab CI.
  • Trivy is a practical general-purpose option for dependency vulnerability scanning in GitLab pipelines.
  • Language-specific tools such as npm audit, pip-audit, composer audit, and cargo audit provide quick ecosystem coverage.
  • Secret detection should block pipelines when real credentials are found, followed by immediate secret rotation.
  • GitLab CI security scanning works best when CI checks are paired with continuous monitoring between pipeline runs.

Frequently Asked Questions

1. Is GitLab dependency scanning free?

GitLab’s built-in dependency scanning is listed as an Ultimate feature. Free and Premium users can still run open source tools such as Trivy, OWASP Dependency-Check, npm audit, pip-audit, composer audit, cargo audit, and gitleaks inside GitLab CI.

2. What’s the best free security scanning option for GitLab?

Trivy is a strong starting point for many teams because it is simple to run in CI and supports multiple ecosystems. For best results, combine it with package-manager audits and secret scanning.

3. Can Vulert integrate with GitLab?

Vulert can support GitLab-based teams by monitoring the same manifest files and SBOMs used in GitLab repositories. CI scans run during pipelines, while Vulert monitors continuously and alerts when new CVEs affect your dependencies.