Back to Gitlabhq

Audit events for secret push protection fail-open scenarios

doc/releases/19/gitlab-19-3-released/spp-new-audit-events.md

19.3.0662 B
Original Source

In earlier versions of GitLab, when secret push protection couldn't complete a scan and allowed a push through unscanned, GitLab provided no customer-visible audit trail. Security and compliance teams had no way to monitor when secret push protection silently allowed a push to their repositories.

GitLab 19.3 and later generates audit events for all fail-open scenarios, including ruleset errors, exceeded file and line limits, scan timeouts, and unexpected errors. Teams can now forward these events to external monitoring and alerting tools to maintain visibility into their security posture.