Item logo image for GitLab MR Vulnerability Widget

GitLab MR Vulnerability Widget

5.0(

4 ratings

)
ExtensionDeveloper Tools22 users
Item media 3 screenshot
Item media 1 screenshot
Item media 2 screenshot
Item media 3 screenshot
Item media 1 screenshot
Item media 1 screenshot
Item media 2 screenshot
Item media 3 screenshot

Overview

Adds a widget to GitLab merge request page showing vulnerabilities detected by Container Scanning.

This extension adds a widget in the Gitlab merge request page showing critical and high vulnerabilities of a container image generated in the associated pipeline. A container scanning job must exist in the pipeline. This job must generate a container scanning report artifact. To add a container scanning job, follow the steps defined here: https://docs.gitlab.com/ee/user/application_security/container_scanning/ The free version of Gitlab supports container scanning but does not support decoration of the merge request with vulnerability details. This extension fills that gap by decorating the merge request with a vulnerability widget. Note: The extension requires configuring a personal access token with "read_api" scope to allow fetching the pipeline artifacts. This token is saved in Chrome storage with encryption and never leaves your browser. To create a personal access token, follow the steps here: https://docs.gitlab.com/ee/user/profile/personal_access_tokens.html Reference: Container scanning job: https://docs.gitlab.com/ee/user/application_security/container_scanning/ Container scanning report artifact: https://docs.gitlab.com/ee/ci/yaml/artifacts_reports.html#artifactsreportscontainer_scanning Personal access token: https://docs.gitlab.com/ee/user/profile/personal_access_tokens.html

5 out of 54 ratings

Google doesn't verify reviews. Learn more about results and reviews.

Details

  • Version
    0.0.1
  • Updated
    October 22, 2024
  • Offered by
    Abhinav Sonkar
  • Size
    25.64KiB
  • Languages
    English (United States)
  • Developer
    Email
    abhinavcext@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

The developer has disclosed that it will not collect or use your data.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps