GitLab Dependency Scanning Posture Report
Delivers a weekly report on dependency scanning coverage across a GitLab group, what changed, and anything that needs attention.
What this agent does
This read-only agent checks the health of dependency scanning across a GitLab group every week. It finds active projects where dependency scanning does not run, and projects whose scanning jobs are failing. It summarizes the vulnerabilities that appeared, were resolved, or were dismissed since last week. It flags anything that needs an admin, such as a scan that stopped or dismissals made as an acceptable risk.
The challenge
Dependency scanning only covers projects whose pipelines run it, and gaps in coverage are easy to miss. A new project never gets the scanning job, a pipeline change removes it, or the job fails every run. Dismissals accumulate, and nobody reviews who made them. Admins find out when an auditor reports an old vulnerability.
The solution
The agent checks scanning coverage, job health, and vulnerability activity across the group in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
Find active projects where dependency scanning does not run on the default branch.
- 02
Check job health
Find projects whose dependency scanning jobs failed or have not run in the last week.
- 03
Check activity
Summarize vulnerabilities that appeared, were resolved, or were dismissed since last week.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# GitLab Dependency Scanning Posture Report
## Measurable outcomes
Every week, the admin knows which projects dependency scanning is not covering, what changed across the group, and what needs action. Track covered and uncovered projects and open action items on every run.
## Procedure
Once a week, check every active project in the GitLab group and its subgroups. List the projects where dependency scanning does not run on the default branch. List the projects whose last scanning job failed, with the error, or that have not been scanned in the last week, unless I set another window. Summarize the new Critical and High vulnerabilities, the vulnerabilities resolved, and the vulnerabilities dismissed since the last report, with who dismissed them and the reason. Call out dismissals made as an acceptable risk, since those are decisions someone should review. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs GitLab Ultimate and API read access to the group's projects, pipelines, and vulnerabilities, and nothing more. It never changes projects, pipelines, or vulnerabilities. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools