Quickstart
Four ways in, same result: a required check on every pull request that refuses known vulnerabilities and unmet approved criteria: fail closed.
GitHub Actions
# .github/workflows/security-gate.yml
name: Security gate
on:
pull_request:
permissions:
contents: read
pull-requests: write # for the summary comment
jobs:
gate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: Baktun-Studio/linebreak-gate@v1
with:
# fail-on: high # blocking floor; default: critical
license-key: ${{ secrets.LINEBREAK_LICENSE_KEY }}
# Enables the AI code review; leave unset for dependency scan only.
anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }}The Action runs linebreak-gate scan, always runs report, posts one PR summary comment (updated in place on every push, never spammed), uploads the JSON report and audit artifacts as a workflow artifact, and fails the check per the scan’s exit code.
Make it a real boundary: require the check
A CI job that can be ignored is a dashboard, not a gate. In your repo: Settings → Branches → Branch protection rules → your default branch → “Require status checks to pass before merging” → add the gate job. From then on, a PR carrying a critical CVE cannot be merged through the GitHub UI.
The setup App (near-one-click)
Installing the LineBreak Gate GitHub App replaces the manual steps: pick repos at install time and the App opens one setup pull request per repo containing the canonical gate workflow, with the secrets and branch-protection deep links in the PR body. Merge it, add the secret, done. Boundaries, by design:
- Setup only, never scanning. Scans run on your own GitHub runners via the workflow file; your code never touches LineBreak servers. Uninstalling the App changes nothing: the workflow lives in the repo.
- Minimal permissions: contents + workflows write (required to commit the workflow file), pull requests write (for the setup PR), metadata read. Nothing else.
- Idempotent: a repo that already has the workflow, an already-open setup PR, and webhook redeliveries all converge to a no-op; archived repos are skipped.
One command from the terminal
pip install linebreak-gate && linebreak-gate initinit writes the workflow file, offers to store the secrets (via the GitHub CLI) and to require the gate check on the default branch, and prints the exact settings links for anything it can’t do itself. Idempotent: it never overwrites an existing workflow without --force.
Any other CI (GitLab example)
The CLI is a plain Python package with strict exit codes (0 pass / 1 blocking findings / 2 tool error, fail closed). Any CI that respects exit codes gets the same enforcement:
# .gitlab-ci.yml
security-gate:
image: python:3.11
script:
- pip install linebreak-gate
- linebreak-gate scan
- linebreak-gate reportInstall osv-scanner in the job image for full multi-ecosystem coverage (the gate falls back to npm audit for npm projects otherwise). Mark the job as required (no allow_failure) and protect the branch.
Next: the spec loop
linebreak-gate spec new # scaffold a draft: fill it with any tool,
# or distill your existing PRD
linebreak-gate spec approve .linebreak/spec-draft.yml \
--approver "Ana Lopez <ana@example.com>" # a human on the record
linebreak-gate mcp install --editor claude-code # or: cursor · codexFrom here, linebreak-gate check enforces the approved criteria in CI and the MCP bridge serves them to your coding agent while it works. Full command detail in the CLI reference.