linebreakDocumentation · linebreak-gate

Configuration

One file, committed to the repo: .linebreak/gate.yml. A boundary whose strictness depends on individual machines is not a boundary; here, a threshold change is itself a PR: visible, reviewable, attributable.

The full file

# .linebreak/gate.yml (all keys optional)
fail_on: critical            # blocking floor: critical (default) | high | medium | low
exclude_paths:               # paths the scanners skip
  - fixtures
  - "sandbox/*"
code_scan: auto              # AI code review: auto (default) | on | off
criteria:
  enforce: true              # acceptance-criteria checking
                             # (default: true when a spec bundle exists)
approvals:                   # signed-approval verification (Pro)
  public_keys:
    - kid: "2026-01"
      public_key: "<base64 Ed25519 verifying key>"

Key by key

KeyDefaultEffect
fail_oncriticalSeverity floor that blocks the merge. A finding at or above the floor fails the check.
exclude_pathsnoneGlob patterns the scanners skip (fixtures, sandboxes, vendored test data).
code_scanautoThe AI code review pass. auto runs it when a key is available (ANTHROPIC_API_KEY takes precedence over LINEBREAK_LICENSE_KEY); off also makes report ignore a committed code verdict, so scan and report can never disagree.
criteria.enforcetrue*Acceptance-criteria checking. *Default is on whenever an approved spec bundle exists; turning it off is an explicit (and visible) edit to this file.
approvals.public_keysemptyEd25519 verifying keys (kid + base64 key). See below: presence of a non-empty list is what makes signatures required.

Precedence

Explicit CLI flag / Action input → .linebreak/gate.yml → built-in default (critical). An invalid config exits 2: fail closed, never a silent fallback to defaults.

Signature verification keys

The presence of a non-empty approvals.public_keys list is the only switch that flips the gate from “unsigned OK” to “signature required.” It deliberately keys off this config, never off whether the spec manifest happens to carry a signature. Otherwise an attacker could strip the signature to downgrade to honest-unsigned. Multiple keys (distinct kids) let old and new approvals both verify across a key rotation. A malformed key is a config error (exit 2), not a silent verification miss.

GitHub Action inputs

InputEffect
fail-onBlocking floor for this workflow; overrides gate.yml.
license-keyLINEBREAK_LICENSE_KEY: enables the hosted AI code review and signed approvals (Pro).
anthropic-api-keyANTHROPIC_API_KEY: runs the AI code review on your own model key (takes precedence; never billed as credits).
storyScope of the acceptance-criteria check: all (default), auto (this branch’s story, inferred from feat/<id> or story/<id>, else started stories only), or a story id. Recommended: auto on pull requests, all at release.
manualwarn lists manual criteria without a sign-off as pending without blocking; block fails the check. Empty means warn on pull_request and block on every other event.
stagerelease (default) evaluates every criterion; pr skips criteria marked check.when: release in the spec and lists them as release-only, so a shared-staging regression does not block every PR.