## Shiftleft CICD Integration

In this post, we are going to show how to integrate Shiflett into a modern CI/CD orchestrator like [Gitlab](https://about.gitlab.com/). We will take the perspective of an application developer that integrates Shiftleft blades into the CI/CD pipeline and how it leverages Shiftleft information to start solving vulnerabilities detected in the code, container image that the pipeline builds as well as an infrastructure project that uses Terraform.

### Shiftleft Modules

The following is a short description of Shiftleft modules also known as blades:

- **code-scan**: Using as input a directory that contains a Git repository, Shiftleft will scan it for vulnerabilities, weak coding practices, sensitive content, and malicious files among other categories.
- **image-scan**: Using as input a container image, compressed into a file, this blade will apply all the capabilities already provided by code-scan and will add on top of that the scanning of OS-level packages included in the container image.
- **iac-assessment**: In combination with CloudGuard, Infrastructure as code assessment allows users to apply policies to their Terraform projects. The mechanism to define those rules is by making use of [CloudGuard Governance Specification Language](https://sc1.checkpoint.com/documents/CloudGuard_Dome9/Documentation/PostureManagement/GSL.html) (GSL). A high-level, human-friendly language.

---

### Upcoming Events

- **Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats**  
  [Virtual](https://community.checkpoint.com/t5/CheckMates-Events/Under-the-Hood-Check-Point-and-Illumio-Modern-Network-Defense/ev-p/279701)  
  Tue 28 Jul 2026 @ 11:00 AM (EDT)

- **AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway**  
  [In-Person](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Masters-E12-READY-OR-NOT-Securing-the-AI-Enterprise/ev-p/277411)  
  Tue 11 Aug 2026 @ 11:30 AM (EDT)

---

### Community Interaction

- [Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/215751?t:ac=board-id/DevSecOps/message-id/51&t:cp=kudos/contributions/tapletcontributionspage&ticket=88ESh11tcz2g_-1)

---

**Can shiftleft be used for on premise security or just cloud?** We are using Kubernetes & podman on premise.

**Response:** Yes if you're running a locally hosted solution like Gitlab or Jenkins it can work there too - you just need to authenticate it against your CloudGuard solution.

---

### Technical Details

**Error Code:** MEDIA_ERR_NETWORK  
Technical details:

HLS playlist request error at URL: https://manifest.prod.boltdns.net/manifest/v1/hls/v4/clear/6058022097001/d4fb8e88-9198-419f-bc28-c0f60662bfa9/10s/master.m3u8?fastly_token=NmE2NjJiMjdfMjFkNWEzNDc1NGUwOWM4MDZlODUxOTcyZTEzZTExZTMzMTg3OGZiM2NkM2I1NDQ3NTA3NjdjMGQ3NGQ1ODI2MQ%3D%3D.
