Inspiration

Modern AI coding tools can generate code quickly, but security review still often happens too late: after the merge request is opened, after reviewers are overloaded, or after risky changes are already close to production. I wanted to build something that gives AI the right codebase context and turns every GitLab merge request into a real-time security checkpoint.

SecureOrbit was inspired by the GitLab Transcend Hackathon theme: context is everything. Instead of scanning code as isolated files, SecureOrbit focuses on understanding the merge request, the changed code, the security impact, and the policy risk in one workflow.

What it does

SecureOrbit is a real-time AI security gate for GitLab merge requests.

When a merge request is created or updated, SecureOrbit analyzes the code changes and identifies security risks such as:

Hardcoded secrets and credentials Risky authentication or authorization changes Unsafe API patterns Policy violations Sensitive code paths that need extra review High-risk changes that should be blocked or escalated

The goal is simple: help developers and security teams catch risky changes before they reach production, while giving reviewers clear, actionable feedback instead of noisy scan results.

SecureOrbit produces a security review summary that explains what changed, why it matters, and what should be fixed before merge.

How I built it

I built SecureOrbit as a GitLab merge request security review workflow.

The project uses GitLab merge request context as the main input, analyzes changed files and diffs, and applies security-focused detection logic to identify risky patterns. The system is designed around the idea that security tools should understand the developer workflow, not interrupt it.

The main components include:

A merge request analysis flow Security rule checks for secrets, risky patterns, and policy violations A risk scoring approach for changed code Review output that can be used by developers, reviewers, or security teams A demo-ready workflow for showing how SecureOrbit reviews a real merge request

I focused on making the project practical, easy to test, and directly relevant to real-world DevSecOps workflows.

Challenges I ran into

One challenge was balancing useful security feedback with noise reduction. Security tools are only valuable if developers trust the results, so SecureOrbit needed to focus on findings that are clear, explainable, and actionable.

Another challenge was designing the project so it could work in a hackathon environment while still feeling like a realistic enterprise security workflow. I wanted the demo to be simple enough for judges to test, but strong enough to show how this could evolve into a production-ready security gate.

I also had to think carefully about how to represent risk. Not every finding should block a merge request. Some issues should warn, some should escalate, and some should require security review.

Accomplishments that I am proud of

I am proud that SecureOrbit connects directly to a real developer pain point: catching security issues inside the merge request workflow before they become production problems.

Key accomplishments include:

Built a working security-focused merge request review concept Created a practical DevSecOps use case for GitLab Orbit-style code context Designed the project around real security engineering workflows Made the output understandable for both developers and security reviewers Focused on actionable findings instead of generic vulnerability noise

SecureOrbit shows how AI-native development can become safer when the AI has the right project context.

What I learned

I learned that context is the difference between a basic scanner and a useful security reviewer. A simple pattern match can detect a secret, but understanding whether a code change affects authentication, authorization, sensitive APIs, or production risk requires deeper project awareness.

I also learned that developer experience matters. A security gate should not just say “blocked.” It should explain the reason, the affected code, the risk, and the recommended fix.

Most importantly, I learned that AI security tooling is strongest when it helps humans make better decisions instead of replacing human review entirely.

What's next for SecureOrbit

Next, we want to expand SecureOrbit into a more complete AI-native security review platform for GitLab.

Future improvements include:

Deeper GitLab Orbit integration for richer codebase context Automatic merge request comments with fix recommendations More advanced policy-as-code support Risk scoring based on file sensitivity and historical project context Integration with CI/CD security checks Support for compliance evidence and audit trails A dashboard for security teams to track risky merge requests across projects

The long-term vision is for SecureOrbit to become an intelligent security reviewer that understands the codebase, protects the merge pipeline, and helps teams ship faster without sacrificing security.

Built With

  • ai-code-review
  • api
  • devsecops
  • fastapi
  • git
  • gitlab
  • gitlab-ci/cd
  • gitlab-merge-requests
  • gitlab-orbit
  • json
  • markdown
  • policy-as-code
  • python
  • repository
  • rest-apis
  • risk-scoring
  • secret-detection
  • security-rule-engine
  • webhooks
Share this project:

Updates

Submission history