GitLab CI
A ready-made job scans every merge request on your own GitLab runner and can comment on the merge request.
Setup
- Create an API key.
- In the project, go to Settings → CI/CD → Variables and add
DAGSEC_API_KEY, masked. - Optional, for the merge request comment: create a project access token with the
apiscope and the Reporter role, and add it as a masked variableDAGSEC_GITLAB_TOKEN. - Add to
.gitlab-ci.yml:
yaml
include:
- remote: https://dagsec.net/ci/gitlab.ymlThe job runs on merge request pipelines, in the test stage, on an alpine:3.20 image. The template is at dagsec.net/ci/gitlab.yml.
Variables
Override them in your own dagsec: job:
yaml
dagsec:
variables:
DAGSEC_FAIL_UNDER: "60"| Variable | Default | Meaning |
|---|---|---|
DAGSEC_API_KEY | required | Your API key |
DAGSEC_GITLAB_TOKEN | unset | Project access token for the merge request comment |
DAGSEC_FAIL_UNDER | 40 | Health score threshold |
DAGSEC_PATH | . | Directory to scan |
DAGSEC_SERVER | https://app.dagsec.net | dagsec server |
GIT_DEPTH | 0 | Full clone; dagsec reads git history |
gitlab.com and self-managed GitLab
- gitlab.com: the job requests an ID token with audience
dagsec. It proves which project is running; dagsec then asks GitLab whether the project is public. The Free plan scans public projects. - Self-managed GitLab: its tokens can't be verified from outside, so the job names the project instead (
gitlab_project=group/project). This works on paid plans.
What happens in a job
- Installs
git,curlandjq, and marks the checkout as a safe directory. - Downloads the scanner with your key (and the ID token on gitlab.com). A refusal fails the job with the reason.
- Scans the checkout, with secrets checked only in commits since
CI_MERGE_REQUEST_DIFF_BASE_SHA. - Prints the report in the job log and saves it as the
dagsec-report.mdartifact, shown on the merge request as dagsec report. - With
DAGSEC_GITLAB_TOKEN, creates or updates one merge request comment marked<!-- dagsec-report -->. - Exits
0(passed),1(findings) or2(scan error). Only0passes.
Requirements
- An x86-64 Linux runner that can pull
alpine:3.20and reachapp.dagsec.net. - Merge request pipelines (the job's rule is
$CI_PIPELINE_SOURCE == "merge_request_event").