Skip to content

GitLab data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On GitLab, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the GitLab connector needs.

Checks (5)

severity: high Group Public Visibility fix difficulty: easy #

Change GitLab group visibility from Public to Private or Internal

  1. Navigate to GitLab Group Settings > General > Visibility, project features, permissions
  2. Change the group visibility to 'Private' or 'Internal'
  3. Review subgroup and project visibility settings

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Group Sharing Unlocked fix difficulty: easy #

Enable Share with group lock in GitLab to prevent projects from being shared outside the group

  1. Navigate to Group > Settings > General > Permissions
  2. Enable Share with group lock
  3. Save changes
  4. Review existing project shares

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Group Forking Allowed Outside fix difficulty: easy #

Prevent project forking outside the GitLab group to protect source code

  1. Navigate to Group > Settings > General > Permissions
  2. Enable Prevent project forking outside the group
  3. Save changes
  4. Review existing forks for unauthorized copies

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high Group Sharing Outside Organization fix difficulty: easy #

Prevent GitLab groups from being shared outside the organization hierarchy

  1. Navigate to Group > Settings > General > Permissions
  2. Enable Prevent sharing groups outside the hierarchy
  3. Save changes
  4. Audit existing group shares

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium Public Project fix difficulty: easy #

Review public GitLab projects and change visibility to Private or Internal if they contain sensitive code

  1. Review whether the project should be public
  2. Change visibility to 'Private' or 'Internal' if it contains sensitive code
  3. If it must be public, ensure no secrets or credentials are in the repository

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

More GitLab checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial