GitLab
Visualize GitLab users, groups, code repositories, and merge requests, map GitLab users to employees and development/security trainings, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
- Release Notes
Installation
To use this integration, JupiterOne requires a GitLab personal access token configured with read access (read_api scope) and
the API base URL, such as https://gitlab.com).
Configuration in JupiterOne
To install the GitLab integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select GitLab. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
Account Name by which you'd like to identify this GitLab account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen Tag with Account Name is selected. -
Description that will further assist your team when identifying the integration instance.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
Personal Access Token configured for read access in GitLab.
Once your token has expired, the integration will no longer run successfully, and the token will be revoked from your GitLab account. You will need to create another token to replace the expired one.
- Your GitLab API Base URL (e.g.,
https://gitlab.com, or your self-managed instance URL).
Data Volume Configuration
Control how much data is ingested from GitLab to manage storage and processing.
Ingestion Windows (Time Ranges)
| Field | Description | Default | Options |
|---|---|---|---|
| Merge Requests Ingestion Window | Ingestion window for updated merge requests (days ago) | 90 | 90, 180, 275, 365 |
How it affects data volume: Longer windows increase the number of merge requests ingested from GitLab.
Data Filtering Options
| Field | Type | Description | Default |
|---|---|---|---|
| Included Vulnerability Severities | Multi-select | Select vulnerability severities to ingest | Medium, High, Critical |
| Included Vulnerability States | Multi-select | Select vulnerability states to ingest | Confirmed, Detected |
| Included Vulnerability Report Types | Multi-select | Select vulnerability report types to ingest | None (all disabled by default) |
| Ingest Regular Users Only | Boolean | Skip all bot accounts including project and group bots | false |
How it affects data volume:
- Severity filtering reduces vulnerabilities by excluding lower-severity findings. By default, only Medium, High, and Critical severabilities are ingested.
- State filtering limits vulnerabilities to selected states. By default, only Confirmed and Detected vulnerabilities are ingested (Dismissed and Resolved are excluded).
- Report type filtering allows selecting specific vulnerability scan types (SAST, DAST, Container Scanning, etc.). By default, all types are disabled and must be explicitly enabled.
- User filtering, when enabled, excludes bot accounts from ingestion, reducing the number of user entities.
Click Create after all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Roles
RBAC roles that must be assigned to the integration principal.
Show Roles (5)
DeveloperGuestMaintainerOwnerReporter
OAuth Scopes
OAuth scopes that must be granted to the application or service principal.
Show OAuth Scopes (2)
read_apiread_user
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (14)
/api/graphql/api/v4/groups/:id/variables/api/v4/projects/:id/api/v4/projects/:id/approval_rules/api/v4/projects/:id/approvals/api/v4/projects/:id/pipelines/api/v4/projects/:id/pipelines/:pipeline_id/api/v4/projects/:id/pipelines/:pipeline_id/jobs/api/v4/projects/:id/protected_branches/api/v4/projects/:id/push_rule/api/v4/projects/:id/variables/api/v4/projects/:id/vulnerability_findings/api/v4/users/api/v4/users/:id
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (18)
- https://docs.gitlab.com/api/merge_request_approvals/
- https://docs.gitlab.com/api/project_push_rules/
- https://docs.gitlab.com/api/projects/
- https://docs.gitlab.com/api/protected_branches/
- https://docs.gitlab.com/ee/api/graphql/reference/#groups
- https://docs.gitlab.com/ee/api/graphql/reference/#mergerequestcommits
- https://docs.gitlab.com/ee/api/graphql/reference/#projectbranchrules
- https://docs.gitlab.com/ee/api/graphql/reference/#querycurrentuser
- https://docs.gitlab.com/ee/api/graphql/reference/#querymetadata
- https://docs.gitlab.com/ee/api/group_level_variables.html
- https://docs.gitlab.com/ee/api/jobs.html
- https://docs.gitlab.com/ee/api/labels.html
- https://docs.gitlab.com/ee/api/merge_requests.html
- https://docs.gitlab.com/ee/api/pipelines.html
- https://docs.gitlab.com/ee/api/project_level_variables.html
- https://docs.gitlab.com/ee/api/projects.html
- https://docs.gitlab.com/ee/api/users.html
- https://docs.gitlab.com/ee/api/vulnerability_findings.html
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (14)
| Step | Roles | OAuth Scopes | Endpoints |
|---|---|---|---|
| Fetch Approval Rules | Developer | read_api | /api/v4/projects/:id/approval_rules |
| Fetch Branch Rules | Maintainer | read_api | /api/graphql |
| Fetch CI jobs | Reporter | read_api | /api/v4/projects/:id/pipelines/:pipeline_id/jobs |
| Fetch CI/CD variables | Maintainer, Owner | read_api | /api/v4/projects/:id/variables, /api/v4/groups/:id/variables |
| Fetch merge requests | Reporter | read_api | /api/graphql |
| Fetch MR commits | Reporter | read_api | /api/graphql |
| Fetch pipelines | Reporter | read_api | /api/v4/projects/:id/pipelines, /api/v4/projects/:id/pipelines/:pipeline_id |
| Fetch Project Config | Developer | read_api | /api/v4/projects/:id, /api/v4/projects/:id/approvals |
| Fetch Project Labels | Guest | read_api | /api/graphql |
| Fetch Project Push Rules | Maintainer | read_api | /api/v4/projects/:id/push_rule |
| Fetch projects | Guest | read_api | /api/graphql |
| Fetch Protected Branches | Developer | read_api | /api/v4/projects/:id/protected_branches |
| Fetch users | Reporter | read_user, read_api | /api/graphql, /api/v4/users, /api/v4/users/:id |
| Fetch Vulnerability Findings | Developer | read_api | /api/graphql, /api/v4/projects/:id/vulnerability_findings |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Account | gitlab_account | Account |
| Approval Rule | gitlab_approval_rule | Rule |
| Branch Rule | gitlab_branch_rule | Rule |
| CI Job | gitlab_ci_job | Task |
| CI/CD Variable | gitlab_secret | Secret |
| Commit | gitlab_commit | CodeCommit |
| Finding | gitlab_finding | Finding |
| Group | gitlab_group | Group |
| Label | gitlab_label | Record |
| Merge Request | gitlab_merge_request | CodeReview, PR |
| Pipeline | gitlab_pipeline | Workflow |
| Project | gitlab_project | CodeRepo, Project |
| Project Setting | gitlab_project_setting | Configuration |
| Push Rule | gitlab_push_rule | Configuration |
| User | gitlab_user | User |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
gitlab_account | HAS | gitlab_group |
gitlab_account | HAS | gitlab_project |
gitlab_approval_rule | ALLOWS | gitlab_user |
gitlab_approval_rule | ALLOWS | gitlab_group |
gitlab_branch_rule | ALLOWS | gitlab_user |
gitlab_branch_rule | ALLOWS | gitlab_group |
gitlab_group | HAS | gitlab_group |
gitlab_group | HAS | gitlab_project |
gitlab_group | HAS | gitlab_user |
gitlab_group | HAS | gitlab_secret |
gitlab_merge_request | HAS | gitlab_commit |
gitlab_merge_request | HAS | gitlab_pipeline |
gitlab_pipeline | HAS | gitlab_ci_job |
gitlab_project | HAS | gitlab_user |
gitlab_project | HAS | gitlab_finding |
gitlab_project | HAS | gitlab_merge_request |
gitlab_project | HAS | gitlab_label |
gitlab_project | HAS | gitlab_branch_rule |
gitlab_project | HAS | gitlab_push_rule |
gitlab_project | HAS | gitlab_project_setting |
gitlab_project | HAS | gitlab_approval_rule |
gitlab_project | HAS | gitlab_pipeline |
gitlab_project | HAS | gitlab_secret |
gitlab_user | APPROVED | gitlab_merge_request |
gitlab_user | OPENED | gitlab_merge_request |
Gitlab Account
gitlab_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
enterprise * | boolean | ||
id * | string | ||
name * | string | ||
revision * | string | ||
vendor * | string | ||
version * | string |
Gitlab Approval Rule
gitlab_approval_rule inherits from Rule
| Property | Type | Description | Specifications |
|---|---|---|---|
approvalsRequired | number | null | Number of approvals this rule requires (API approvals_required). | |
isAppliedToAllProtectedBranches | boolean | null | Whether the rule applies to all protected branches (API applies_to_all_protected_branches). | |
isContainingHiddenGroups | boolean | null | Whether the rule includes groups the token cannot see (API contains_hidden_groups). | |
protectedBranches | array | null | Names of protected branches this rule applies to (API protected_branches[].name). | |
reportType | string | null | Report type for report_approver rules (API report_type). | |
ruleType | string | null | Approval rule type: regular, code_owner, report_approver or any_approver (API rule_type). |
Gitlab Branch Rule
gitlab_branch_rule inherits from Rule
| Property | Type | Description | Specifications |
|---|---|---|---|
allowForcePush | boolean | null | Whether force push is allowed on matching branches. | |
codeOwnerApprovalRequired | boolean | null | Whether merges to matching branches require code owner approval (Premium/Ultimate). | |
createdOn | number | ||
id * | string | ||
isDefault | boolean | null | Whether the rule protects the project default branch (GraphQL only). | |
isInherited | boolean | null | Whether the protection is inherited from the parent group and cannot be changed at project level (REST inherited, Premium/Ultimate). | |
isProtected * | boolean | ||
matchingBranchesCount | number | null | Number of existing branches that match the rule (GraphQL only). | |
mergeAccessLevelDescriptions | array | null | Human-readable descriptions of every merge access entry, including user and group grants. | |
mergeAccessLevels | array | null | Role access levels allowed to merge (0 = No one, 30 = Developer, 40 = Maintainer, 60 = Admin). | |
name * | string | ||
pushAccessDeployKeyIds | array | null | Deploy key ids allowed to push (push_access_levels[].deploy_key_id). | |
pushAccessLevelDescriptions | array | null | Human-readable descriptions of every push access entry, including user and group grants. | |
pushAccessLevels | array | null | Role access levels allowed to push and merge (0 = No one, 30 = Developer, 40 = Maintainer, 60 = Admin). Individual user and group grants are ALLOWS relationships to gitlab_user / gitlab_group. | |
unprotectAccessLevelDescriptions | array | null | Human-readable descriptions of every unprotect access entry, including user and group grants. | |
unprotectAccessLevels | array | null | Role access levels allowed to unprotect the branch. | |
updatedOn | number |
Gitlab Ci Job
gitlab_ci_job inherits from Task
| Property | Type | Description | Specifications |
|---|---|---|---|
artifactFileTypes | array of strings | List of artifact file types produced by the job (e.g. archive, metadata, trace). | |
artifactsExpireOn | number | Timestamp when this job's artifacts expire. | |
coverage | number | Reported test coverage percentage for the job, if configured. | |
duration | number | Job execution duration in seconds. | |
erasedOn | number | Timestamp the job log was erased, if it was (audit signal). | |
failureReason | string | GitLab-provided enum describing why the job failed (e.g. script_failure, runner_system_failure). | |
finishedOn | number | Timestamp the job finished (epoch millis). | |
hasArtifacts | boolean | True when the job produced one or more artifacts. | |
isAllowedToFail | boolean | True if the job is permitted to fail without failing the pipeline. | |
isArchived | boolean | True when the job has been archived. | |
isRunnerActive | boolean | True when the runner is active. | |
isRunnerShared | boolean | True when the runner is shared (cross-project pool). | |
isTag | boolean | True when the job ran for a Git tag. | |
pipelineId * | number | Numeric ID of the pipeline this job belongs to. | |
projectId * | number | Numeric ID of the project this job belongs to. Used in _key for global uniqueness. | |
queuedDuration | number | Time the job spent queued before starting, in seconds. | |
ref | string | Branch or tag this job ran against. | |
runnerDescription | string | Human-readable description of the runner that executed the job. | |
runnerId | number | Numeric ID of the runner that executed the job (if any). | |
runnerType | string | Runner scope: instance_type, group_type, or project_type. | |
sha | string | Commit SHA the job ran against. | |
source | string | Trigger source for the parent pipeline (push, schedule, merge_request_event, ...). | |
stage | string | CI stage the job belongs to (e.g. build, test, deploy). | |
startedOn | number | Timestamp the job started executing (epoch millis). | |
tagList | array of strings | Runner tags requested by the job (.gitlab-ci.yml tags). | |
userId | number | Numeric ID of the user who triggered the job. | |
userUsername | string | Username of the user who triggered the job. |
Gitlab Commit
gitlab_commit inherits from CodeCommit
| Property | Type | Description | Specifications |
|---|---|---|---|
authoredOn | number | ||
authorEmail | string | ||
authorName | string | ||
branch * | string | ||
committedOn | number | ||
committerEmail | string | ||
committerName | string | ||
commitWebLink * | string | ||
createdOn | number | deprecated: true | |
id * | string | ||
merge * | boolean | ||
message * | string | ||
name * | string | ||
shortId * | string | ||
title | string | ||
versionBump * | boolean | ||
webLink * | string |
Gitlab Finding
gitlab_finding inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
createVulnerabilityFeedbackDismissalPath * | string | deprecated: true | |
createVulnerabilityFeedbackIssuePath * | string | deprecated: true | |
createVulnerabilityFeedbackMergeRequestPath * | string | deprecated: true | |
description | string | ||
dismissalFeedback | string | deprecated: true | |
dismissalReason | string | ||
falsePositive | boolean | ||
identifiers | array of strings | ||
links | array of strings | ||
projectFingerprint | string | deprecated: true | |
reportType | string | ||
scanner.externalId | string | ||
scanner.name | string | ||
scanner.vendor | string | ||
solution | string | ||
state | string | ||
uuid | string | ||
vulnerabilityPath | string |
Gitlab Group
gitlab_group inherits from Group
| Property | Type | Description | Specifications |
|---|---|---|---|
autoDevopsEnabled | boolean | ||
createdOn | number | ||
description | string | ||
emailsDisabled | boolean | ||
fullName * | string | ||
fullPath * | string | ||
id * | string | ||
lfsEnabled | boolean | ||
mentionsDisabled | boolean | ||
name * | string | ||
parentGroupId | string | ||
path * | string | ||
projectCreationLevel | string | ||
requestAccessEnabled | boolean | ||
requireTwoFactorAuthentication | boolean | ||
shareWithGroupLock | boolean | ||
subgroupCreationLevel | string | ||
twoFactorGracePeriod | number | ||
visibility | string | ||
webUrl * | string |