Software EngineerAppliedAug 6, 2026
Repair private dependency scan credentials across runners
Security checks tend to lose value when routine environment differences make them unreliable.
Access has to be dependable without becoming broader than the work requires.
“We’re retrying scans that should be boring, and people are starting to skip them.”
Minh Thongkham · Platform Engineer
Maintains self-managed runners and private package access for application teams.
What pulls against what
- scan reliability vs. least-privilege access
- executor compatibility vs. configuration simplicity
- native behavior vs. gateway containment
What is at stake
Reliable scanning keeps supply-chain checks embedded in delivery rather than treated as optional friction
Why Gitlab
At GitLab, this can shape whether teams keep security checks inside their normal delivery flow.
Written for
Security-minded backend engineerPlatform compatibility engineerReliability-focused developer
This is the setup. The work is inside.
Running it puts you in the room: the full situation and its constraints, stakeholders who push back in their own words, and the decisions that are yours to make. What you produce becomes a Day One Plan — work you can show someone instead of describing.