GitLab Workflow

Prerequisites

Add XEIZE_TOKEN and a GitLab API token as CI/CD variables. The GitLab API token can be named XEIZE_GITLAB_API_TOKEN or GITLAB_API_TOKEN.

XEIZE Token

Obtain an XEIZE_TOKEN to use XEIZE with GitLab Workflow.

GitLab PAT Token

To post comments, provide a GitLab personal access token through XEIZE_GITLAB_API_TOKEN or GITLAB_API_TOKEN with the following scope. When both variables are set, XEIZE_GITLAB_API_TOKEN takes precedence; GITLAB_API_TOKEN is used only when that value is empty.

  • api

The token's user must also have project membership permissions to view the code and comment on merge requests. read_api is read-only and insufficient; write_repository does not authorize REST API access. See GitLab's access token scopes and project permissions.

For token creation, see the GitLab PAT guide.

Scan result language

Add LANG to variables to choose the language of SAST, Secret, and IaC findings and comments on the merge request.

yaml
variables:
  LANG: "JP"

Supported values are KO (Korean), EN (English), and JP (Japanese). Korean is the default when LANG is unset.

Examples

SAST

yaml
image: alpine:3.24
stages:
  - sast
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
  LANG: "JP"
sast:
  stage: sast
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab ./xez_ci

Secret

yaml
image: alpine:3.24
stages:
  - secret
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
  MODE: secret
  LANG: "JP"
secret:
  stage: secret
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab ./xez_ci

IaC

yaml
image: alpine:3.24
stages:
  - iac
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
  MODE: iac
  LANG: "JP"
iac:
  stage: iac
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab ./xez_ci

Blocking merges with LEVEL

yaml
image: alpine:3.24
stages:
  - sast
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
sast:
  stage: sast
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab LEVEL=high ./xez_ci

Filtering findings with AUDIT LEVEL

yaml
image: alpine:3.24
stages:
  - iac
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
iac:
  stage: iac
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab MODE=iac LEVEL=high AUDIT_LEVEL=low ./xez_ci

Push pipeline without an MR

This runs SAST, Secret, and IaC with MODE=all when code is pushed to develop, then builds and deploys after a successful scan. Add XEIZE_TOKEN as a CI/CD variable.

yaml
workflow:
  rules:
    - if: '$CI_PIPELINE_SOURCE == "push" && $CI_COMMIT_BRANCH == "develop"'

stages: [security, build, deploy]

security:
  stage: security
  image: alpine:3.24
  allow_failure: false
  variables:
    GIT_DEPTH: "0"
    MODE: all
    LEVEL: medium
  before_script:
    - apk add --no-cache git curl
  script: |
    curl -fsSL -H "X-XEZ-TOKEN: $XEIZE_TOKEN" https://download.xeize.dev/ci/ci_linux_x64 -o /tmp/xez_ci
    chmod +x /tmp/xez_ci
    GIT_PLATFORM=gitlab /tmp/xez_ci

build:
  stage: build
  needs: [security]
  script:
    - ./ci/build.sh

deploy:
  stage: deploy
  needs: [build]
  script:
    - ./ci/deploy.sh

Replace build/deployment commands and runner settings for your project while preserving the security → build → deploy dependencies. See common settings for scan scope and error handling.

Related pages1