Security findings
A finding is what one scanner reported in one pipeline; a vulnerability is the tracked record GitLab keeps of a finding across pipelines. security_finding.list lists the findings of one pipeline, filtered by severity, report type, scanner or state, which is what a pipeline’s security report showed.
Sample questions
Section titled “Sample questions”- “What did the SAST scan find in pipeline 456?”
- “List the critical findings of the latest pipeline”
- “Show the secret detection findings of pipeline 123”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such assecurity_finding.list, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_security_findingwithactionset to the action’s name, such aslist, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_list_security_findings, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 1:
- Free: 0
- Premium: 0
- Ultimate: 1
Read-only actions: 1 of 1, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.
| Action | Individual |
|---|---|
security_finding.list | gitlab_list_security_findings |
security_finding.list
Section titled “security_finding.list”List a pipeline’s security report findings with severity, scanner, report-type and state filters, severity sorting and keyset pagination. Returns: matching findings with UUID, title, severity and original severity, report type, scanner, identifiers (CVE, CWE, OWASP), location, state, who dismissed it and why, evidence with the recorded HTTP exchange, proposed remediations, report links, and linked vulnerability state. See also:
vulnerability.list,vulnerability.pipeline_security_summary,vulnerability.severity_count.
- Meta-tool:
gitlab_security_finding, actionlist - Individual tool:
gitlab_list_security_findings - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
pipeline_iid | string | yes | Pipeline IID within the project |
project_path | string | yes | Full path of the project (e.g. my-group/my-project) |
after | string | no | Cursor for forward pagination (from previous response end_cursor) |
before | string | no | Cursor for backward pagination (from previous response start_cursor). The page size comes from last, or from first when last is omitted |
first | integer | no | Number of items to return (default 20, max 100) |
last | integer | no | Number of items to return from the end of the range (backward pagination). Cannot be combined with first |
report_type | string[] | no | Filter by report type: SAST, DAST, DEPENDENCY_SCANNING, CONTAINER_SCANNING, SECRET_DETECTION, COVERAGE_FUZZING, API_FUZZING, CLUSTER_IMAGE_SCANNING, SARIF. SARIF needs GitLab 18.11, and an older GitLab drops it and answers with no findings |
scanner | string[] | no | Filter by scanner external IDs |
severity | string[] | no | Filter by severity: CRITICAL, HIGH, MEDIUM, LOW, INFO, UNKNOWN |
sort | string (severity_desc, severity_asc) | no | Sort order: severity_desc (default) or severity_asc |
state | string[] (DETECTED, CONFIRMED, DISMISSED, RESOLVED) | no | Filter by state: DETECTED, CONFIRMED, DISMISSED, RESOLVED |