Skip to content

GitLab CI ​

A ready-made job scans every merge request on your own GitLab runner and can comment on the merge request.

Setup ​

  1. Create an API key.
  2. In the project, go to Settings → CI/CD → Variables and add DAGSEC_API_KEY, masked.
  3. Optional, for the merge request comment: create a project access token with the api scope and the Reporter role, and add it as a masked variable DAGSEC_GITLAB_TOKEN.
  4. Add to .gitlab-ci.yml:
yaml
include:
  - remote: https://dagsec.net/ci/gitlab.yml

The job runs on merge request pipelines, in the test stage, on an alpine:3.20 image. The template is at dagsec.net/ci/gitlab.yml.

Variables ​

Override them in your own dagsec: job:

yaml
dagsec:
  variables:
    DAGSEC_FAIL_UNDER: "60"
VariableDefaultMeaning
DAGSEC_API_KEYrequiredYour API key
DAGSEC_GITLAB_TOKENunsetProject access token for the merge request comment
DAGSEC_FAIL_UNDER40Health score threshold
DAGSEC_PATH.Directory to scan
DAGSEC_SERVERhttps://app.dagsec.netdagsec server
GIT_DEPTH0Full clone; dagsec reads git history

gitlab.com and self-managed GitLab ​

  • gitlab.com: the job requests an ID token with audience dagsec. It proves which project is running; dagsec then asks GitLab whether the project is public. The Free plan scans public projects.
  • Self-managed GitLab: its tokens can't be verified from outside, so the job names the project instead (gitlab_project=group/project). This works on paid plans.

What happens in a job ​

  1. Installs git, curl and jq, and marks the checkout as a safe directory.
  2. Downloads the scanner with your key (and the ID token on gitlab.com). A refusal fails the job with the reason.
  3. Scans the checkout, with secrets checked only in commits since CI_MERGE_REQUEST_DIFF_BASE_SHA.
  4. Prints the report in the job log and saves it as the dagsec-report.md artifact, shown on the merge request as dagsec report.
  5. With DAGSEC_GITLAB_TOKEN, creates or updates one merge request comment marked <!-- dagsec-report -->.
  6. Exits 0 (passed), 1 (findings) or 2 (scan error). Only 0 passes.

Requirements ​

  • An x86-64 Linux runner that can pull alpine:3.20 and reach app.dagsec.net.
  • Merge request pipelines (the job's rule is $CI_PIPELINE_SOURCE == "merge_request_event").