Trending:

GitLab rolls out organization-wide security risk dashboard in beta

Dashboard visualization showing organization-wide security risk
TechStaged-owned

Summary

  • GitLab now aggregates vulnerabilities and a single risk score across the entire organization.
  • The organization security dashboard is in beta for GitLab.com Ultimate users.
  • Previously, getting an organization-wide view required manual pulling data into spreadsheets or scripts.

GitLab has introduced a beta feature that aggregates vulnerabilities and a single risk score across an entire organization. The organization-wide security dashboard is available to Ultimate customers on GitLab.com and is designed for enterprises with many top-level groups, reducing the need for manual data gathering.

The dashboard consolidates findings across top-level groups and scanners, enabling security teams to see the organization’s overall risk on one screen and act on it without stitching data together by hand.

HOW THE RISK SCORE IS CALCULATED

The organization-wide risk score is computed from several factors, including the severity and age of open vulnerabilities, whether a vulnerability appears on the Known Exploited Vulnerabilities (KEV) list, and its Exploit Prediction Scoring System (EPSS) score. This helps leaders prioritize where the organization is most exposed to threats rather than counting every finding equally. TechStaged has also covered GitLab Duo Self-Hosted gains Bring-Your-Own-Model support with Microsoft Foundry.

WHAT THE DASHBOARD AGGREGATES AND SHOWS

The dashboard aggregates data across every top-level group and every scanner your teams run, bringing together GitLab’s scanners and any third-party scanners that output SARIF reports. It provides a consolidated read on risk, with organization-wide charts and per-project views.

  • Consolidated risk score across the organization
  • Vulnerabilities over time (30, 60, 90 days)
  • Vulnerabilities by age to highlight stale items
  • Open vulnerabilities by severity
  • Top 10 Common Weakness Enumeration (CWE) patterns
  • Filtering by project or report type (SAST or dependency scanning)

HOW TO ENABLE AND PREREQUISITES

Enabling the organization-wide dashboard requires specific setup. Four conditions must be in place before the dashboard can display organization-level risk: an Organization with multiple top-level groups (Organizations (Beta)); Owner role at the Organization level; Advanced search and advanced vulnerability management active; and at least one security scanner with a completed scan on the default branch.

  • Create an Organization with multiple top-level groups (Settings > General > Advanced)
  • Have Owner role access to the Organization-level area
  • Enable advanced search and advanced vulnerability management
  • Have at least one security scanner with a completed scan on the default branch

AVAILABILITY AND WHAT COMES NEXT

The organization security dashboard is available in beta on GitLab.com for Ultimate customers. If an organization has not yet migrated to Ultimate, GitLab notes that a free trial can be started to access organization-level visibility into risk.

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.