Skip to main content
Source Code Managers

GitLab

Connect GitLab to import every project in a group and its subgroups into Guard as repository assets.

The GitLab Integration in PGP

The GitLab integration in the Praetorian Guard Platform (PGP) imports the projects in a GitLab group as repository assets. PGP connects to GitLab with a Personal Access Token (PAT) and works with both gitlab.com and self-hosted GitLab. Setup has two steps: create a Personal Access Token in GitLab, then configure the integration in PGP.

What is imported

  • Every project in the group and its subgroups becomes a repository asset. Forks are skipped, and PGP records whether each project is public.
  • PGP also lists the group's members and imports the public projects each member owns in their personal namespace, at low priority. Forks are skipped here too.

Creating a Personal Access Token in GitLab

First, access the Personal Access Tokens page in GitLab. You can do this by signing into GitLab and either going directly to the Personal Access Tokens page or navigating there through your profile settings (Profile icon → Edit profile → Access Tokens). On the Personal Access Tokens page, click "Add new token".

When creating the token, provide a descriptive name and set an appropriate expiration date. Under "Select scopes," enable both read_api and read_repository:

  • read_api lets PGP list the group, its subgroups, its projects, and its members.
  • read_repository lets PGP clone each project for scanning.

The integration is read-only. PGP does not need the api or write_repository scopes.

After clicking "Create personal access token", GitLab will display your token - copy it immediately as it won't be shown again.

Finding Your GitLab Group URL

To locate your group URL, visit your Group page in GitLab and navigate to "Group settings". Under the Advanced section in Group General settings, you'll find your group's base URL. For a self-hosted instance, the URL starts with your GitLab server's address, for example https://gitlab.example.com/mygroup.

GitLab Dedicated Secure Networking

If your organization uses GitLab Dedicated with Secure Networking enabled, Guard must be able to reach your GitLab environment from the public IP ranges used by the platform and Praetorian VPN egress.

Before connecting the integration, add the following IP ranges to your GitLab Dedicated IP allowlist:

  • 66.45.78.0/24 — Guard Platform
  • 3.133.170.58 — Guard Platform Validation IP
  • 35.188.30.0 — Praetorian VPN Egress #1
  • 35.196.215.192 — Praetorian VPN Egress #2

Without this allowlisting step, Guard may be unable to authenticate to GitLab or scan repositories successfully.

Configuring the Integration in PGP

In PGP's interface, go to the Integrations page and click "Add Integration". You can find GitLab listed under the Source Code Managers section, or use the search bar to locate it directly.

In the integration configuration window, fill in two fields:

  • Personal Access Token (PAT): the token you created
  • (Parent) GitLab Group URL: your GitLab group URL

Save to complete the setup. PGP validates the token against the group first.

Fix Merge Requests

When Constantine finds a vulnerability, it generates a validated patch. For GitLab projects, the patch is shown on the risk in PGP, and you can review it and click Copy diff to apply it yourself. PGP cannot open merge requests in GitLab. Opening a pull request from PGP is available only for GitHub repositories.

Webhooks

The GitLab integration does not use webhooks, and you do not need to configure any in GitLab. PGP finds new projects the next time the integration runs.

Troubleshooting

  • GitLab rejected the supplied personal access token: the token is invalid, expired, or revoked. Create a new token.
  • The GitLab token authenticated successfully but cannot access group '<group>': the token's user is not a member of the group, or the token lacks the read_api scope.
  • Enter a valid GitLab group URL: enter the full group URL, for example https://gitlab.com/<group>.

If you need help with this integration, contact support@praetorian.com.

Still need help? Ask the team