Coding assistants, like the Claude security guidance plugin and Claude Security, can flag and fix common vulnerabilities in code as it's written, in the same session. Teams already using Claude security guidance and Claude Security can plug that context directly into GitLab through the GitLab MCP server and keep their existing workflow. Merge request approval policies hold any merge with unresolved critical findings until a named approver signs off, so dismissed or missed vulnerabilities can't reach production quietly. Compliance controls guarantee a scan runs on every merge request, and every finding surfaces in the merge request and vulnerability report, visible to a human. Compliance controls guarantee a scan runs on every merge request, and every finding surfaces in the merge request and vulnerability report, visible to a human.