Skip to content

Rule catalogue

Rule IDs are stable machine-readable identifiers intended for configuration, JSON, SARIF, and CI policy.

This page is generated from the same metadata used by the list-rules CLI command.

Registered rules: 47.

Project

Rule ID Default severity Description
project.archived-state info Reports active or archived project state.
project.contributing-present info A recognised contribution guide exists.
project.default-branch medium A default branch exists.
project.description-present low Project description is configured.
project.license-present low A recognised licence file exists.
project.readme-present medium A recognised README file exists.
project.repository-nonempty medium Repository contains content.
project.security-present info A recognised security policy exists.
project.topics-present low Project topics are configured.
project.visibility info Reports observed project visibility.

Governance

Rule ID Default severity Description
governance.approval-rules low Project approval rules require approvals.
governance.default-branch-protected high Default branch protection is enabled.
governance.direct-merge info Reports developer merge capability.
governance.direct-push medium Reports developer direct-push capability.
governance.discussions-resolved low Unresolved discussions block merge.
governance.merge-requests-enabled medium Merge requests are enabled.
governance.merge-strategy info Reports the configured merge method.
governance.pipeline-required medium A successful pipeline is required before merge.
governance.source-branch-cleanup info Automatic source-branch cleanup is enabled.
governance.squash-strategy info Reports the configured squash policy.

CI

Rule ID Default severity Description
ci.artifact-expiry low Jobs with artifacts define explicit expiry.
ci.auto-cancel info Reports pending-pipeline auto-cancel configuration.
ci.branch-mr-behavior info Reports branch and merge-request pipeline signals.
ci.cache-scope low Cache mappings use explicit keys.
ci.config-parseable high GitLab CI YAML is statically parseable.
ci.config-present medium GitLab CI configuration can be located.
ci.includes-resolvable high Static local CI includes resolve on the default branch.
ci.mutable-image-tags medium Detects explicit container images using the :latest tag.
ci.resource-group-mode info Reports resource-group process mode.
ci.workflow-rules info Reports top-level workflow rules.

Dynamic includes and external CI configuration that cannot be resolved safely are reported as unknown/not applicable rather than failed.

CI/CD variables

Rule ID Default severity Description
variables.environment-scope info Reports variable environment scopes.
variables.hidden info Reports hidden-variable metadata.
variables.inventory info Inventories safe CI/CD variable metadata and keys.
variables.masking low Reports unmasked CI/CD variable keys.
variables.protection low Reports unprotected CI/CD variable keys.
variables.variable-type info Reports GitLab variable types.

Variable values are not retained in snapshots or findings.

Pipeline history

Rule ID Default severity Description
pipelines.history info Reports whether recent bounded pipeline history exists.
pipelines.job-coverage info Reports completeness of failed-job metadata inspection.
pipelines.repeated-jobs medium Detects repeatedly failing job names.
pipelines.repeated-stages low Detects repeatedly failing stage names.
pipelines.status-summary info Summarises recent pipeline statuses.

Releases

Rule ID Default severity Description
releases.recency info Reports latest observed tag and release timestamps.
releases.release-notes low Checks that releases contain non-empty notes.
releases.releases-present info Reports whether GitLab releases exist.
releases.semver-consistency low Optional SemVer-shaped tag consistency policy.
releases.tag-consistency medium Checks that observed releases correspond to repository tags.
releases.tags-present info Reports whether repository tags exist.

SemVer is not required by default.