Integrations / GitLab

    Junglewise for GitLab

    Authorize Junglewise on GitLab and pick the projects it may see. It checks their dependencies against new vulnerabilities, reviews merge requests as they open, and drafts fixes as merge requests of its own. Read access to start; nothing merges unless you say so.

    OAuth app. Read access to start. About 1 min to set up.

    Connecting GitLab

    How you connect it

    1. Step 1

      Authorize Junglewise with GitLab. GitLab shows you every scope it asks for first.

    2. Step 2

      Choose the projects. Each starts switched off until you enable it.

    3. Step 3

      Junglewise scans the enabled projects straight away, then every 24 hours. Setup takes about a minute.

    What Junglewise reads

    Watched around the clock

    • Dependencies

      Each enabled project's dependency list, with the lock files as a fallback, checked daily and on demand against new vulnerabilities.

    • Merge requests

      New and updated merge requests, so the agent can review them before they merge.

    • Pushes and pipelines

      Pushes and pipeline results, so a failing or suspicious run is noticed.

    • Vulnerability findings

      The findings GitLab already shows, which the agent reads when it investigates a project.

    What it can change

    Only with your approval

    • Open a fix merge request

      A branch, a commit and a merge request with the reasoning, for you to review like any other.

    • Review merge requests

      Comments on security issues in a merge request, as a review.

    • Merge, only when it is safe

      If you allow it, a fix merges once its pipeline has passed, the merge request is mergeable and no reviewer has asked for changes.

    Each change waits for you unless you set an auto mode rule for that kind of fix, and every applied change is logged with what it changed.

    GitLab questions

    Does Junglewise keep a copy of my source code?
    No. It reads what it needs to produce a finding or draft a fix, and keeps the finding, not the code.
    Which scopes does it need to open merge requests?
    To read, Junglewise asks for read_api and read_repository. To draft fixes it also needs the api scope. Without it Junglewise only reads, and tells you which scope is missing.
    How do I disconnect?
    Revoke Junglewise under Applications in your GitLab user settings. Junglewise loses access immediately.

    See what's lurking out there. It takes a minute.

    Start with a free scan of your domain. When you're ready for the inside view, try Team free for 14 days.

    Start 14-day free trial