All integrations

GitLab Integration with DefectDojo

GitLab is a comprehensive DevSecOps platform that integrates application security testing capabilities including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secret detection, container scanning, and dependency scanning directly into CI/CD pipelines to identify vulnerabilities, exposed credentials, and insecure dependencies throughout the software development lifecycle. The platform delivers security findings directly within merge requests and IDEs where developers work, enabling continuous vulnerability detection from code commit through production deployment while providing automated compliance monitoring against standards such as SOC 2, ISO 27001, and PCI-DSS with audit-ready evidence collection.

Data Granularity: What Gets Imported

The following fields are captured from GitLab results and surfaced in DefectDojo findings:

FieldSourceNotes
TitleFinding name from the scanMatched to the tool's own naming
SeverityCritical / High / Medium / Low / InfoMapped from the tool's own severity scale
DescriptionFinding detail from the reportIncludes what the issue is and why it matters
MitigationRemediation guidanceWhere the tool provides it

Importing Into DefectDojo

Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:

{
  "scan_type": "GitLab",
  "engagement": "<engagement-id>",
  "file": "results.json"
}