Skip to content

Add security scanning to CI pipeline

Sarah German requested to merge ci-security-scans into main

What does this MR do and why?

Copies over security scanning from gitlab-docs, dropping Ruby-related scanners (Brakeman) and the deprecated nodejs scanner.

gitlab-docs version: https://gitlab.com/gitlab-org/gitlab-docs/-/blob/main/.gitlab/ci/security.gitlab-ci.yml?ref_type=heads

Pipeline output

Individual jobs:

Merge request acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Sarah German

Merge request reports