Vulnerabilities
Vulnerabilities are the records GitLab keeps of what its security scanners found, tracked across pipelines. These actions list a project’s vulnerabilities with filters, read one, triage it (confirm, dismiss, resolve, or revert it to detected), count a project’s vulnerabilities by severity, and summarize the security reports of one pipeline. What a single pipeline’s scanners reported is on Security findings.
Sample questions
Section titled “Sample questions”- “List the critical vulnerabilities of project 42”
- “Dismiss vulnerability 42 as a false positive”
- “How many vulnerabilities does project 42 have by severity?”
- “Which scanners ran in pipeline 123?”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such asvulnerability.confirm, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_vulnerabilitywithactionset to the action’s name, such asconfirm, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_confirm_vulnerability, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 8:
- Free: 0
- Premium: 0
- Ultimate: 8
Read-only actions: 4 of 8, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served.
| Action | Individual |
|---|---|
vulnerability.confirm | gitlab_confirm_vulnerability |
vulnerability.dismiss | gitlab_dismiss_vulnerability |
vulnerability.get | gitlab_get_vulnerability |
vulnerability.list | gitlab_list_vulnerabilities |
vulnerability.pipeline_security_summary | gitlab_pipeline_security_summary |
vulnerability.resolve | gitlab_resolve_vulnerability |
vulnerability.revert | gitlab_revert_vulnerability |
vulnerability.severity_count | gitlab_vulnerability_severity_count |
vulnerability.confirm
Section titled “vulnerability.confirm”Confirm a vulnerability as a real finding. Returns: the updated vulnerability with its new confirmed state and timestamp. See also:
vulnerability.get,vulnerability.dismiss,vulnerability.resolve.
- Meta-tool:
gitlab_vulnerability, actionconfirm - Individual tool:
gitlab_confirm_vulnerability - Tier: Ultimate
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
id | string | yes | Vulnerability GID (e.g. gid://gitlab/Vulnerability/42) |
vulnerability.dismiss
Section titled “vulnerability.dismiss”Dismiss a vulnerability with a dismissal reason. Returns: the updated vulnerability with its new dismissed state and timestamp. See also:
vulnerability.get,vulnerability.confirm,vulnerability.revert.
- Meta-tool:
gitlab_vulnerability, actiondismiss - Individual tool:
gitlab_dismiss_vulnerability - Tier: Ultimate
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
id | string | yes | Vulnerability GID (e.g. gid://gitlab/Vulnerability/42) |
comment | string | no | Reason for dismissal |
dismissal_reason | string (ACCEPTABLE_RISK, FALSE_POSITIVE, MITIGATING_CONTROL, NOT_APPLICABLE, USED_IN_TESTS) | no | Dismissal reason: ACCEPTABLE_RISK, FALSE_POSITIVE, MITIGATING_CONTROL, USED_IN_TESTS, NOT_APPLICABLE |
vulnerability.get
Section titled “vulnerability.get”Get a single vulnerability by global ID. Returns: title, description, severity, state and its comment, report type, scanner, identifiers, CVSS assessments, EPSS and known-exploit data, location, solution, report links, a leaked token’s status, who confirmed, dismissed or resolved it, linked issues, and merge request. See also:
vulnerability.list,vulnerability.dismiss,vulnerability.confirm.
- Meta-tool:
gitlab_vulnerability, actionget - Individual tool:
gitlab_get_vulnerability - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
id | string | yes | Vulnerability GID (e.g. gid://gitlab/Vulnerability/42) |
vulnerability.list
Section titled “vulnerability.list”List a project’s vulnerabilities with severity, state, scanner, and report-type filters plus keyset pagination. Returns: matching vulnerabilities with UUID, title, severity, state, report type, scanner, identifiers, location, CVSS and EPSS data, who confirmed, dismissed or resolved each, detection time, and web URL. See also:
vulnerability.get,vulnerability.severity_count,security_finding.list.
- Meta-tool:
gitlab_vulnerability, actionlist - Individual tool:
gitlab_list_vulnerabilities - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_path | string | yes | Full path of the project (e.g. my-group/my-project) |
after | string | no | Cursor for forward pagination (from previous response end_cursor) |
before | string | no | Cursor for backward pagination (from previous response start_cursor). The page size comes from last, or from first when last is omitted |
first | integer | no | Number of items to return (default 20, max 100) |
has_issues | boolean | no | Filter by whether a linked issue exists |
has_resolution | boolean | no | Filter by whether a resolution exists |
last | integer | no | Number of items to return from the end of the range (backward pagination). Cannot be combined with first |
report_type | string[] | no | Filter by report type: SAST, DAST, DEPENDENCY_SCANNING, CONTAINER_SCANNING, CONTAINER_SCANNING_FOR_REGISTRY, SECRET_DETECTION, COVERAGE_FUZZING, API_FUZZING, CLUSTER_IMAGE_SCANNING, SARIF, GENERIC |
scanner | string[] | no | Filter by scanner external IDs |
severity | string[] | no | Filter by severity: CRITICAL, HIGH, MEDIUM, LOW, INFO, UNKNOWN |
sort | string (severity_desc, severity_asc, detected_desc, detected_asc) | no | Sort order: severity_desc, severity_asc, detected_desc, detected_asc |
state | string[] | no | Filter by state: DETECTED, CONFIRMED, DISMISSED, RESOLVED |
vulnerability.pipeline_security_summary
Section titled “vulnerability.pipeline_security_summary”Summarize a pipeline’s security scan results. Returns: per-scanner vulnerability and scanned-resource counts for the pipeline (SAST, DAST, and other report types), the scans that ran with their status, errors and warnings, and the first resources a DAST scan requested. See also:
vulnerability.severity_count,vulnerability.list.
- Meta-tool:
gitlab_vulnerability, actionpipeline_security_summary - Individual tool:
gitlab_pipeline_security_summary - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
pipeline_iid | string | yes | Pipeline IID (internal ID within the project) |
project_path | string | yes | Full path of the project (e.g. my-group/my-project) |
vulnerability.resolve
Section titled “vulnerability.resolve”Resolve a vulnerability after it is fixed. Returns: the updated vulnerability with its new resolved state and timestamp. See also:
vulnerability.get,vulnerability.confirm,vulnerability.revert.
- Meta-tool:
gitlab_vulnerability, actionresolve - Individual tool:
gitlab_resolve_vulnerability - Tier: Ultimate
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
id | string | yes | Vulnerability GID (e.g. gid://gitlab/Vulnerability/42) |
vulnerability.revert
Section titled “vulnerability.revert”Revert a vulnerability back to the detected state. Returns: the updated vulnerability with its restored detected state. See also:
vulnerability.get,vulnerability.dismiss,vulnerability.resolve.
- Meta-tool:
gitlab_vulnerability, actionrevert - Individual tool:
gitlab_revert_vulnerability - Tier: Ultimate
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
id | string | yes | Vulnerability GID (e.g. gid://gitlab/Vulnerability/42) |
vulnerability.severity_count
Section titled “vulnerability.severity_count”Count a project’s vulnerabilities grouped by severity. Returns: critical, high, medium, low, info, and unknown counts. See also:
vulnerability.list,vulnerability.pipeline_security_summary.
- Meta-tool:
gitlab_vulnerability, actionseverity_count - Individual tool:
gitlab_vulnerability_severity_count - Tier: Ultimate
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_path | string | yes | Full path of the project (e.g. my-group/my-project) |