Your next merge request ships a known-exploited CVE. We catch it first.
OpsArmor Gate is a GitLab merge-request security gate. Scanners run on MRs and default branches. Findings land in one inbox — scored, evidenced, and triaged before merge.
Google SSO for operators · GitLab PAT age-encrypted · Self-host
GitLab
Merge requests + default branch. Not a GitHub App. No cloud OIDC keys.
6
Scanner engines — Trivy, Grype, Semgrep, Checkov, Kingfisher, ChainArmor
30+
Import formats — SARIF, CycloneDX, GitLab, OpenVEX, Wazuh, Nuclei, Gitleaks, Snyk…
§03One GitLab install. One findings inbox.
No GitHub App. No “zero stored keys” claim. Operators sign in with Google SSO. Each install stores a GitLab PAT, envelope-encrypted with age. Scanners comment on the MR; the inbox is where work happens.
Inbox · open · assigned to you KEV CVE-2021-23337 lodash@4.17.20 critical SECRET AKIA••••WXYZ .gitlab-ci.yml:42 critical SAST sql-injection src/api/users.go high actions: snooze · ignore · assign · scan again
§04From GitLab install to an inbox you can work.
Install once with a GitLab PAT. Scanners run on the next merge request and on the default branch. Findings are fingerprinted, scored, and opened in the inbox — with one MR comment, not ten duplicate alerts.
GitLab connected.
Google SSO for operators. A GitLab personal access token, envelope-encrypted with age. Webhooks on MRs. No GitHub App to install.
Scanners run.
Trivy, Grype, Semgrep, Checkov, Kingfisher, ChainArmor on the clone. Default-branch coverage plus the merge-request diff. Import SARIF / CycloneDX when CI already scanned it.
Findings scored.
Fingerprint, EPSS, KEV, VEX. Same finding across scanners is one row. AI assessment is advisory and must bind to that evidence.
Inbox + MR comment.
One comment on the merge request. The work happens in Gate: assign, snooze, ignore, notes. Autofix stays off unless you enable it for eligible findings.
§05Scanners you already trust.
Gate runs them on the GitLab clone and accepts the reports you already produce. Same fingerprint, same inbox row.
1
2
3
4
5
6
7
8
9
10
11{
"scanner": "grype",
"package": "lodash@4.17.20",
"cve": "CVE-2021-23337",
"kev": true,
"epss": 0.84,
"fixed": "4.17.21",
"source": "merge_request+default"
} 1
2
3
4
5
6
7
8
9
10
11{
"scanner": "semgrep",
"check_id": "go.lang.security.sql",
"path": "src/api/users.go",
"line": 84,
"severity": "high",
"snippet": "db.Query(fmt.Sprintf(...))"
} 1
2
3
4
5
6
7
8
9
10
11{
"scanner": "kingfisher",
"kind": "aws_access_key",
"path": ".gitlab-ci.yml",
"line": 42,
"prefix": "AKIA••••WXYZ",
"note": "rotate; do not autofix"
}Also live: Checkov (Terraform / Kubernetes / Dockerfile policy), ChainArmor (OSV.dev), OpenVEX, and import of SARIF, CycloneDX, GitLab, Wazuh, Nuclei, Gitleaks, Snyk, and more. Not a Pulumi / AWS CDK blast-radius product.
§06Changelog.
What actually landed on main. Preview while Gate is still being finished — planned items are issues, not slogans.
AI assessments must cite scanner evidence. Scorecard, routing, and currentness so a stale verdict cannot pretend to be live. Operators keep the decision.
SARIF, CycloneDX, GitLab, OpenVEX, Wazuh, native scanner JSON, and 30+ tool formats. Assign, severity override, notes, package ignore. Autofix stays off.
Autofix can stage a GitLab fix for eligible findings — off until you enable it. Dedicated Terraform / IaC review and IaC Autofix are still open P1s. Merge-blocking needs GitLab Premium external status checks. None of these are on by default.
§07Pricing. Per operator. Waitlist while Gate finishes.
Preview rates for GitLab teams. Seats are humans who triage findings — bots are free. Self-host is the same product, on your VPS.
$0preview
- ✓ Google SSO · GitLab PAT
- ✓ MR + default-branch scans
- ✓ Findings inbox
- ✓ Scan import
- — Org SLA · self-host
$2923/ seat / mo
- ✓ Everything in Free
- ✓ Evidence-bound AI triage
- ✓ Assign · snooze · ignore rules
- ✓ Members & invites
- ◔ Eligible Autofix opt-in
$5947/ seat / mo
- ✓ Everything in Team
- ✓ Org SLA tracking
- ✓ Org triage + ignore rules
- ✓ Audit log of operator decisions
- ◔ Merge-blocking GitLab Premium
Talk to us
- ✓ Everything in Business
- ✓ Self-host on your VPS
- ✓ Your allowlist, your age key
- ✓ MCP for agent workflows
- ✓ Named onboarding
Google SSO for operators. GitLab PAT stored age-encrypted. Scanners plus optional Autofix write — Autofix is off by default. Seats = humans who triage; service accounts are free. This is OpsArmor Gate, not a GitHub IaC blast-radius product.
Join the preview waitlist.
Tell us your GitLab (SaaS or self-hosted) and where findings pile up today — CVE inbox, secrets, or SAST. We reply in batches. No GitHub App to install.