Skip to content

Integration

GitLab integration

GoSentrix qualifies evidence from GitLab as one input to release-evidence verification. It does not replace GitLab; it evaluates whether the signals from GitLab satisfy customer-defined policy for a consequential decision.

Evidence status:design target

What signal enters GoSentrix

Commits, merge request metadata, approval states, CI/CD pipeline job results, vulnerability reports, dependency scanning results, container scanning outputs, issue boards, and compliance framework signals originating from GitLab.

What GoSentrix verifies

GoSentrix qualifies each signal by freshness, traceability to the artifact and commit, and corroboration with review, scanning, and runtime evidence. It checks whether the combined GitLab signals satisfy the policy version active for a release decision.

What decision or proof it can support

Supports authorization decisions for merge readiness, release eligibility, and remediation verification when GitLab is a primary source of engineering and security truth.

What GoSentrix does not claim

  • GoSentrix does not replace GitLab, GitLab CI, or GitLab security scanners.
  • GoSentrix does not host source code or run pipelines.
  • GoSentrix does not guarantee that all GitLab signals are available or authoritative.
  • GoSentrix does not independently detect vulnerabilities in source code.

Frequently asked questions

Does GoSentrix replace GitLab?

No. GoSentrix is release-evidence verification software. It does not replace GitLab, GitLab CI, or GitLab security features. It consumes signals from GitLab as evidence inputs and evaluates whether they satisfy customer-defined policy for a consequential decision.

What GitLab signals can GoSentrix qualify?

GoSentrix can qualify commits, merge request metadata, approval rules, pipeline job results, vulnerability reports, dependency scanning results, container scanning outputs, issue state, and compliance framework signals exported from GitLab.

Explore agent-neutral evidence verification.

GoSentrix qualifies evidence from existing tools and evaluates it against versioned policy for consequential software decisions.