linebreak-gate documentation
One package, three jobs at the git/CI boundary: a fail-closed security gate, an approved-spec bridge for coding agents, and a git-committed evidence record of who approved what.
What it is
You cannot force an agent (or a human) to follow a spec at writing time, but you can refuse non-compliant code at the merge boundary. linebreak-gate runs as a pre-merge check in any CI:
- Dependency CVE scan: free, no key required. osv-scanner across every ecosystem (npm, PyPI, Go, Cargo, Maven, …) with an
npm auditfallback for npm projects. Every finding is concrete: CVE ID, CVSS, advisory link. - AI code review (SAST): Pro. An LLM security review of first-party source (injection, broken auth, secret exposure, SSRF, unsafe deserialization, crypto misuse) with adversarial verification: three independent skeptic votes per finding. Enabled by
LINEBREAK_LICENSE_KEY(hosted) orANTHROPIC_API_KEY(your own key, takes precedence). Without a key the dependency scan still runs and this pass is skipped with a notice. - Acceptance-criteria enforcement. A human approves the spec on the record; the gate checks the work against it in CI, and the MCP bridge serves the same approved spec to the agent while it writes, read-only.
Principle: the gate blocks and can propose; it never auto-clears on an agent’s say-so. A human approves the fix or records an override (with a reason and an approver) in a git-committed audit file. No LLM clearing an LLM.
The exit-code contract
Three exit codes are the whole integration surface. Any CI that respects exit codes gets the same enforcement:
| Code | Meaning |
|---|---|
0 | Pass: no blocking findings at or above the configured floor. |
1 | Blocking findings: the check fails. |
2 | Tool or config error: the check fails. Fail closed: a scanner crash, a broken gate.yml, or a denied entitlement is never a clean pass. |
Sections
Distribution
linebreak-gate is Apache-2.0. Releases land on PyPI and the public source mirror Baktun-Studio/linebreak-gate from CI, and every change passed our own gate first: CVE scan plus human-approved criteria, the same discipline we sell. Reference the GitHub Action as @v1, never @main.