Getting started with XCA | Singapore Government Developer Portal
Have feedback? Please

All project code hosted on SHIP-HATS 2.0 GitLab are transparently onboarded to XCA.

XCA CI runs in two situations:

  1. When a Merge Request is created: Scan changed files in the Merge Request.
  2. When new code is committed to the default branch: Scan all files on the default branch.

To access XCA findings:

  1. When a Merge Request is created: Wait for the job to complete and check the security scanning Merge Request widget.
    Fig 1: A screenshot of the Merge Request.


  2. When new code is committed to the default branch: Wait for the job to complete and check the project’s Security & Compliance > Vulnerability Report page. XCA findings are marked as “XCA” under the Identifier and Tool columns.
    Fig 2: A screenshot of the XCA findings on the Vulnerability Report page.

Last updated 06 March 2023


Was this article useful?
Send this page via email
Share on Facebook
Share on Linkedin
Tweet this page