High-risk tools in Gitlab
9 of the 190 tools in Gitlab are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
gitlab_cancel_pipelineExecuteCancel a running pipeline.
-
gitlab_cancel_pipeline_jobExecuteCancel one running job.
-
gitlab_execute_graphqlExecuteBackward-compatible GraphQL executor. Mutation payloads still honor read-only policy.
-
gitlab_execute_graphql_mutationExecuteExecute GraphQL mutation (disabled in read-only mode).
-
gitlab_play_pipeline_jobExecutePlay a manual job.
-
gitlab_retry_pipelineExecuteRetry failed jobs in pipeline.
-
gitlab_retry_pipeline_jobExecuteRetry one failed job.
-
gitlab_create_pipelineExecuteTrigger a new pipeline.
-
gitlab_merge_merge_requestExecuteMerge an existing merge request.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.