Announcing a New Integration with GitLab Ultimate! - Sonatype Lifecycle & Repository Firewall - Sonatype Community

Announcing a New Integration with GitLab Ultimate!

post by mfrost on Oct 23, 2024

Maura Frost

We’re excited to announce our new integration with GitLab Ultimate! With this update, you can now view detailed vulnerability findings from Lifecycle scans right in your GitLab Vulnerability Report. Plus, your project’s Dependency List will display scan results, highlighting any vulnerabilities found for your components. This enhancement helps streamline your security workflows by keeping critical information in one place, making it easier to manage and address vulnerabilities within your GitLab projects.

You can read more details here. Please let us know in the thread below if you have any questions.

")

")

post by m588 on Feb 21, 2025

Marcus Münzberg

Hi,

we want to use this exciting new integration, but when I put it in my pipeline I am getting:

This GitLab CI configuration is invalid: Component ‘/sonatype-integrations/components/evaluate-ultimate@main’ - content not found.

Our Gitlab Version is on v17.8.2-ee (Ultimate).

Do I have to configure something on Gitlab site?

Greets, Marcus

post by fcoene on Apr 7, 2025

fcoene@gmail.com

Good afternoon,

We tried out this integration but hit an apparent bug in the timestamp parsing code. I created an issue in GitLab ( DateTimeParseException while running create-vulnerability-report (#2) · Issues · sonatype-integrations / Sonatype CI Components · GitLab) but I am not sure anyone is monitoring that. I also asked our Sonatype liaison to create a support ticket.