GitLab Public Repository Posture Audit
Reports the public projects in a GitLab group that fail its security policy, with each failing check.
What this agent does
This read-only agent audits every public project in a GitLab group against the group's security policy. It checks branch protection and merge request approvals, the README, the license, public exposure, the CI/CD job token allowlist, and member access from outside the group. It then reports each project that fails, with the checks it fails.
The challenge
A public project exposes its code, its pipelines, and its access settings to everyone. Projects are made public by mistake, and protections change after a project is created. A default branch loses its approval rule, a former contractor keeps Developer access, or CI/CD job tokens from any other project can reach it. Nobody checks every public project against the policy. Teams learn about these gaps only when someone finds one by chance.
The solution
The agent checks every public project against the same short policy on each run. It reports a check it cannot complete as inconclusive, never as a violation. It refuses to report when the project list is incomplete, so it never presents a partial scan as the whole group. Provides a unified list of noncompliant public projects and the checks to fix.
Workflow
- 01
List projects
List every public, non-archived project in the group and its subgroups, and stop when the list is incomplete.
- 02
Check policy
Check each project for a protected default branch with required approvals, a README, a license, an approved public listing, an enforced CI/CD job token allowlist, and outside member access.
- 03
Report
Report each noncompliant project with its failing checks, and track the noncompliant and total counts.
Agent template
# GitLab Public Repository Posture Audit
## Measurable outcomes
Every public project in the group that fails the security policy is in the report, with each check it fails. Track the noncompliant count on every run. The count falls as owners fix their projects.
## Procedure
For a given GitLab group, list every public, non-archived project in it and its subgroups. Stop and report the failure when the list is shorter than expected. Never present a partial list as the whole group. Check each project against six rules. The default branch is protected, and merge requests into it need at least one approval. A README exists at the root. A license exists at the root. The project is on an allowlist of projects approved to be public. The CI/CD job token allowlist is enforced, so only the projects on it can use their job tokens to reach this project. No member from outside the group has the Developer role or higher. A project that fails any rule is noncompliant. When a setting cannot be read, report the check as inconclusive and a token scope problem, not a violation. I maintain the allowlist, and I add a project only after I review its public exposure.
## Requirements
It needs GitLab API read access to the group's projects, their protected branches, approval rules, CI/CD settings, and members, and nothing more. It never changes a project, its settings, or its members. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools