Kusari at KubeCon NA in Atlanta - Booth 1942

Integrating GitLab and Kusari

Use Kusari’s tools directly in GitLab workflows to improve your supply chain security.

Parth Patel

November 11, 2025

If you’re one of the 31 million developers who use GitLab to ship code faster, we have good news for you: Kusari Inspector is available to add to your CI workflows. 

You already know that speed and security can often feel at odds. The reality is that every code merge introduces new dependencies—and new risks. 

With Kusari Inspector, you can add automated supply chain checks directly into your GitLab CI workflows to catch security and integrity issues before they ever reach production.

Kusari Inspector flags the following right in your merge request—actionable feedback instantly without waiting for a security review or switching tools:

  • Typosquats and malicious dependencies
  • License violations
  • Unmaintained or deprecated packages
  • Credential leaks and code quality issues
  • Vulnerabilities in transitive dependencies

Adding Inspector to GitLab

Giving developers instant feedback on their code reduces rework, saving time, money, and frustration. Using Inspector in your workflow means that developers don’t have to wait for security review or go check in additional tools to get notified of security issues. They get immediate, actionable feedback right in the merge request.

The Kusari Inspector documentation has step-by-step instructions for adding Inspector to your GitLab CI workflow. Because this setup uses our open source kusari-cli tool, the instructions can be easily adapted to other code forges.

Integrating Kusari Platform and GitLab

Adding Inspector to your GitLab workflow isn’t the only way to integrate Kusari. The kusari-uploader tool is available to upload a software bill of materials (SBOM) as part of the build process. By automatically ingesting build-time SBOMs into Kusari Platform, you get the full end-to-end supply chain visibility that Kusari provides.

You’re generating SBOMs to meet regulatory requirements or industry standards, but simply producing an SBOM doesn’t improve your application security. Kusari Platform enriches your SBOMs and builds a deep dependency graph. This gives you the full understanding of your application ecosystem and that you need to quickly identify and remediate vulnerabilities.

The Results

For Developers and Platform Engineers: Security that Fits the Way You Work

By integrating Inspector into your GitLab CI workflows, you can:

  • Get real-time feedback on code quality and security as part of the merge request
  • Reduce context switching between tools and dashboards
  • Minimize rework by catching issues early in development
  • Maintain developer velocity while enforcing secure coding standards

The setup is fast and transparent. The Kusari Inspector documentation includes step-by-step instructions for adding Inspector to your GitLab CI workflow using our open source kusari-cli tool. You can even adapt the configuration for self-managed GitLab or other CI/CD systems.

Security becomes just another part of your pipeline—not another step that slows you down.

For DevSecOps and Security Teams: From SBOMs to Full Supply Chain Intelligence

Inspector is only one piece of the puzzle. To see your entire software supply chain in one place, integrate GitLab with Kusari Platform using the kusari-uploader tool.

As part of your build process, the uploader automatically:

  • Ingests build-time Software Bill of Materials into Kusari Platform
  • Links components across repositories and builds to create a complete dependency graph
  • Tracks vulnerability impact across versions and releases

You may already be generating SBOMs to meet compliance requirements (such as Executive Order 14028, NIST 800-218, or FDA premarket guidance), but raw SBOMs alone don’t provide real security value.

Kusari enriches your SBOMs with critical metadata—maintainer, license, provenance, and security context—so you can:

  • Prioritize vulnerabilities more effectively
  • Trace risk across microservices and teams
  • Respond faster when new CVEs emerge

This gives DevSecOps and security teams the deep visibility they need to protect the software supply chain from end to end.

For Engineering and Security Leaders: Data-Driven Assurance

Integrating Kusari with GitLab enables your teams to:

  • Standardize secure development practices across all projects
  • Reduce rework and bottlenecks, accelerating delivery cycles
  • Gain visibility and measurable risk metrics to report up to leadership
  • Demonstrate compliance and audit readiness with real-time evidence

With Kusari, secure software delivery becomes a scalable system, not a series of manual reviews.

Get Started

Interested in catching issues before they’re merged? 

Like what you read? Share it with others.

Other blog posts 

The latest industry news, interviews, technologies, and resources.

View all posts

Previous

No older posts

Next

No newer posts

Want to learn more about Kusari?

Schedule a Demo
By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.