linebreakDocumentation · linebreak-gate

linebreak-gate documentation

One package, three jobs at the git/CI boundary: a fail-closed security gate, an approved-spec bridge for coding agents, and a git-committed evidence record of who approved what.

What it is

You cannot force an agent (or a human) to follow a spec at writing time, but you can refuse non-compliant code at the merge boundary. linebreak-gate runs as a pre-merge check in any CI:

  • Dependency CVE scan: free, no key required. osv-scanner across every ecosystem (npm, PyPI, Go, Cargo, Maven, …) with an npm audit fallback for npm projects. Every finding is concrete: CVE ID, CVSS, advisory link.
  • AI code review (SAST): Pro. An LLM security review of first-party source (injection, broken auth, secret exposure, SSRF, unsafe deserialization, crypto misuse) with adversarial verification: three independent skeptic votes per finding. Enabled by LINEBREAK_LICENSE_KEY (hosted) or ANTHROPIC_API_KEY (your own key, takes precedence). Without a key the dependency scan still runs and this pass is skipped with a notice.
  • Acceptance-criteria enforcement. A human approves the spec on the record; the gate checks the work against it in CI, and the MCP bridge serves the same approved spec to the agent while it writes, read-only.

Principle: the gate blocks and can propose; it never auto-clears on an agent’s say-so. A human approves the fix or records an override (with a reason and an approver) in a git-committed audit file. No LLM clearing an LLM.

The exit-code contract

Three exit codes are the whole integration surface. Any CI that respects exit codes gets the same enforcement:

CodeMeaning
0Pass: no blocking findings at or above the configured floor.
1Blocking findings: the check fails.
2Tool or config error: the check fails. Fail closed: a scanner crash, a broken gate.yml, or a denied entitlement is never a clean pass.

Sections

Distribution

linebreak-gate is Apache-2.0. Releases land on PyPI and the public source mirror Baktun-Studio/linebreak-gate from CI, and every change passed our own gate first: CVE scan plus human-approved criteria, the same discipline we sell. Reference the GitHub Action as @v1, never @main.