gitlab-ci
Safeguard articles tagged "gitlab-ci" — guides, analysis, and best practices for software supply chain and application security.
4 articles
GitLab CI Security Best Practices for 2026
GitLab CI hands every job a CI_JOB_TOKEN, a runner, and your variables. This guide covers the real attack surface — remote includes, token scope, privileged runners — with hardened .gitlab-ci.yml examples, OIDC, and scanning.
GitLab IaC Scanning: How to Catch Misconfigured Infrastructure
GitLab IaC scanning checks Terraform, Kubernetes, and CloudFormation for insecure settings before they deploy. Here is how to turn it on and make the results actionable.
How to Generate an SBOM in a GitLab CI Pipeline
A working .gitlab-ci.yml for SBOM generation with Syft: CycloneDX report artifacts, a Grype scan stage, and Cosign attestations pushed next to the image.
GitLab CI Security Scanning Setup
Step-by-step guide to enabling SAST, DAST, dependency scanning, and container scanning in GitLab CI pipelines.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.