> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.governanceaicore.com/integrations/git-lab/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.governanceaicore.com/_mcp/server. # GitLab Integration > Connect GitLab for AI governance and compliance scanning # GitLab Integration Integrate GovernanceAI with GitLab for automated repository scanning and compliance checking. ## Setup ### Step 1: Create API Token * Go to **Settings** → **Access Tokens** * Create token with scopes: * `api` - API access * `read_api` - Read repositories * `read_repository` - Read files * Copy the token ### Step 2: Connect in GovernanceAI * **Integrations** → **GitLab** * Enter GitLab URL (e.g., `https://gitlab.com` or your instance) * Paste API token * Click **Connect** * Select projects to scan ### Step 3: Configure Webhooks GovernanceAI creates webhooks for: * **Push events** - Scan on every push * **Merge request events** - Check on MR * **Issues** - Track compliance findings ## Features ✅ **Automated Scanning** * Scan on push * Check on merge requests * Scheduled scans ✅ **Pipeline Integration** * Run in CI/CD pipeline * Create pipeline artifacts * Fail pipeline on violations ✅ **Merge Request Checks** * Report findings as MR comments * Block merge on critical issues * Show diff-only findings ## GitLab CI/CD Integration ```yaml # .gitlab-ci.yml stages: - scan governanceai_scan: stage: scan script: - | curl -X POST https://api.governanceai.com/v1/scans \ -H "Authorization: Bearer $GOVERNANCEAI_API_KEY" \ -d '{ "repository": "'$CI_PROJECT_PATH'", "ref": "'$CI_COMMIT_SHA'", "gitlab_merge_request_id": "'$CI_MERGE_REQUEST_IID'" }' only: - merge_requests - main ``` ## Permissions Required * `api` - Full API access * `read_repository` - Read repository files * `read_api` - Read API data ## Troubleshooting * **Token expired** - Generate new token * **Webhooks not firing** - Check webhook logs in GitLab * **Projects not showing** - Verify token has `api` scope * **MR comments not appearing** - Check project permissions ## Next Steps * **[GitHub Integration](/integrations/git-hub)** - Connect GitHub * **[Azure DevOps](/integrations/azure-dev-ops)** - Connect Azure DevOps * **[Running Scans](/usage-guides/scans)** - Learn scanning > Connect GitLab for AI governance and compliance scanning