GitLab Integration with DefectDojo
GitLab is a comprehensive DevSecOps platform that integrates application security testing capabilities including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secret detection, container scanning, and dependency scanning directly into CI/CD pipelines to identify vulnerabilities, exposed credentials, and insecure dependencies throughout the software development lifecycle. The platform delivers security findings directly within merge requests and IDEs where developers work, enabling continuous vulnerability detection from code commit through production deployment while providing automated compliance monitoring against standards such as SOC 2, ISO 27001, and PCI-DSS with audit-ready evidence collection.
Data Granularity: What Gets Imported
The following fields are captured from GitLab results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "GitLab",
"engagement": "<engagement-id>",
"file": "results.json"
}