Use Kusari’s tools directly in GitLab workflows to improve your supply chain security.
November 11, 2025

If you’re one of the 31 million developers who use GitLab to ship code faster, we have good news for you: Kusari Inspector is available to add to your CI workflows.
You already know that speed and security can often feel at odds. The reality is that every code merge introduces new dependencies—and new risks.
With Kusari Inspector, you can add automated supply chain checks directly into your GitLab CI workflows to catch security and integrity issues before they ever reach production.
Kusari Inspector flags the following right in your merge request—actionable feedback instantly without waiting for a security review or switching tools:
Giving developers instant feedback on their code reduces rework, saving time, money, and frustration. Using Inspector in your workflow means that developers don’t have to wait for security review or go check in additional tools to get notified of security issues. They get immediate, actionable feedback right in the merge request.
The Kusari Inspector documentation has step-by-step instructions for adding Inspector to your GitLab CI workflow. Because this setup uses our open source kusari-cli tool, the instructions can be easily adapted to other code forges.
Adding Inspector to your GitLab workflow isn’t the only way to integrate Kusari. The kusari-uploader tool is available to upload a software bill of materials (SBOM) as part of the build process. By automatically ingesting build-time SBOMs into Kusari Platform, you get the full end-to-end supply chain visibility that Kusari provides.
You’re generating SBOMs to meet regulatory requirements or industry standards, but simply producing an SBOM doesn’t improve your application security. Kusari Platform enriches your SBOMs and builds a deep dependency graph. This gives you the full understanding of your application ecosystem and that you need to quickly identify and remediate vulnerabilities.
By integrating Inspector into your GitLab CI workflows, you can:
The setup is fast and transparent. The Kusari Inspector documentation includes step-by-step instructions for adding Inspector to your GitLab CI workflow using our open source kusari-cli tool. You can even adapt the configuration for self-managed GitLab or other CI/CD systems.
Security becomes just another part of your pipeline—not another step that slows you down.
Inspector is only one piece of the puzzle. To see your entire software supply chain in one place, integrate GitLab with Kusari Platform using the kusari-uploader tool.
As part of your build process, the uploader automatically:
You may already be generating SBOMs to meet compliance requirements (such as Executive Order 14028, NIST 800-218, or FDA premarket guidance), but raw SBOMs alone don’t provide real security value.
Kusari enriches your SBOMs with critical metadata—maintainer, license, provenance, and security context—so you can:
This gives DevSecOps and security teams the deep visibility they need to protect the software supply chain from end to end.
Integrating Kusari with GitLab enables your teams to:
With Kusari, secure software delivery becomes a scalable system, not a series of manual reviews.
Interested in catching issues before they’re merged?
No older posts
No newer posts