GitLab

GitLab Integration

Pensar Console integrates with GitLab.com to scan and secure your repositories. The integration uses OAuth — you authorize Pensar with a single click and there are no personal access tokens to create or rotate.

The GitLab integration connects to gitlab.com. Self-hosted GitLab instances are not currently supported.

Prerequisites

Before connecting GitLab, ensure you have:

  1. A GitLab.com account with access to the repositories you want to scan
  2. Permission to authorize OAuth applications for your account

Connecting GitLab

From Workspace Settings

  1. Navigate to SettingsIntegrationsSource control in your Pensar Console workspace
  2. Find the GitLab row
  3. Click Connect
  4. You’ll be redirected to GitLab’s authorization page (gitlab.com/oauth/authorize)
  5. Review the requested access and click Authorize
  6. You’ll be automatically redirected back to Pensar Console

From Onboarding

When creating a new workspace, you can connect GitLab during the onboarding process by clicking Connect your GitLab account and following the same steps.

Permissions

When you authorize Pensar, the OAuth flow requests the following scopes:

ScopePurpose
apiAccess to the API for fetching projects and creating merge requests for security fixes
read_userRead user information for attribution
read_repositoryRead repository contents for security scanning

Adding Repositories

After connecting GitLab, attach repositories directly to your workspace:

  1. Go to Attack SurfaceRepositories in Pensar Console
  2. Click Add repository
  3. Your GitLab projects appear in the picker — select one or more
  4. Click Attach & continue

Each repository you attach is connected to the workspace and recon / attack-surface analysis launches automatically — there is no separate project to create.

Managing the Integration

Viewing Connection Status

  1. Navigate to SettingsIntegrationsSource control
  2. Find the GitLab row
  3. If connected, you’ll see the GitLab username Pensar is connected as, along with the option to unlink

Reconnecting

If your connection ever stops working, click Unlink in the GitLab row and then Connect again to re-run the OAuth flow.

Unlinking GitLab

To remove the GitLab integration:

  1. Navigate to SettingsIntegrationsSource control
  2. Find the GitLab row
  3. Click Unlink

Unlinking GitLab will prevent Pensar from scanning GitLab repositories. Any repositories attached to your workspace from GitLab will no longer be able to perform scans.

Troubleshooting

Authorization Failed

If the OAuth authorization fails:

  1. Ensure you’re signed in to the correct GitLab.com account
  2. Try clearing your browser cache and cookies
  3. Attempt the connection again from SettingsIntegrationsSource control

Repositories Not Appearing

If your repositories don’t appear in the Add repository picker:

  1. Verify you have at least Developer access to the repositories in GitLab
  2. Try unlinking and reconnecting GitLab to refresh access
  3. Refresh the repository list

Need Help?

If you encounter issues setting up your GitLab integration, please contact our support team at team@pensar.dev.