Skip to main content
Forge scans GitLab projects for AI application code and configuration, then projects each supported signal into Inventory with repository, revision, file, and confidence evidence.

Coverage

Detection

Signals that are ambiguous in isolation require corroborating repository context. Every accepted observation retains the source path, line, content fingerprint, evidence quality, and confidence.

Scan contract

Connection

Setup

  1. Open Settings → Integrations → GitLab and save the namespace, API v4 base URL, authentication mode, and token.
  2. Leave the project list empty to enumerate projects visible to the token, or provide an explicit project allowlist.
  3. Run a sync. Forge records success, observationCount, canonicalInventoryCount, and blockers for each project.
Changing the base URL after a credential has been saved requires token rotation. Production endpoints must use HTTPS and cannot contain credentials, query strings, fragments, or path traversal.

Boundaries

GitLab scanning is static evidence. It does not establish live usage, user identity at runtime, prompt or response content, tool execution, or enforcement. Join it with endpoint, gateway, or cloud telemetry for runtime attribution.