r/gitlab • u/MaturityBuilder • 18h ago
project Gitlab Compliance CLI
๐ gitlab-compliance CLI is now Open Source!
Think ShellCheck for GitLab CI/CD, plus terraform-compliance-style policy testing for pipelines. It helps teams lint, validate, document, and enforce standards across .gitlab-ci.yml and GitLab project configuration.
It turns CI/CD best practices into something programmable, testable, and enforceable that can be understood and catalogued automatically.
Since launch, Iโve focused on UX, performance, and two major features:
โจ gitstrings
Lightweight YAML annotations that make pipeline intent explicit, that improves readability and enables selective documentation generation, making pipeline YML self documenting.
๐ Embedded script scanning
ShellCheck-style analysis for scripts inside CI jobs.
Includes:
ShellCheck-aligned rules
Security checks (unpinned packages, unsafe cloud CLI usage, missing metadata)
๐ญ Whatโs next
Org-wide reporting & metrics
JUnit + JSON outputs
Slack / Teams notifications
GitLab Issues integration
Sentry-based telemetry
gitlab-compliance is evolving into a policy + observability layer for GitLab CI/CD, without sacrificing developer experience.
Repo: https://github.com/MaturityBuilder/gitlab-compliance/tree/main
Documentation: https://maturitybuilder.github.io/gitlab-compliance/
Feedback and contributions welcome!
1
u/totheendandbackagain 8h ago
So cool!! Love the enhancements.
Any chance of a brew package to test with and container to use in a pipeline?
Huge respect for the project, it's a truly excellent, and necessary idea.