Security gate

Block vulnerable code at the merge

Every pull request gets a dependency CVE scan and, with a key, an AI code review with adversarial verification. Nothing vulnerable merges without a named human sign-off, on the record.

UPDATED · AUGUST 2026

One free check in your CI that blocks pull requests carrying known CVEs: fail-closed, human-only overrides, everything on the record. The AI code review and signed attestations are the Pro layer; the dependency scan below is free forever, no account.

Ventanilla 1 · generate your workflow, commit it, require the check. Protected in ~5 minutes.

La Inspectora: never lets a CVE through

Why now

OpenAI, Anthropic, and Microsoft all shipped AI code-security tools in the same month. All of them FIND problems. None of them will say no to a merge, or record who said yes.

That refusal (fail-closed, with a named human on the record) is this gate's whole job. SARIF ingest from any finder is on the roadmap: one neutral boundary, whatever scanner you run.

Block on

Save as .github/workflows/security-gate.yml, or let the buttons below do it for you.

.github/workflows/security-gate.yml
name: Security gate
on:
  pull_request:

permissions:
  contents: read
  pull-requests: write # for the summary comment

jobs:
  gate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
      - uses: Baktun-Studio/linebreak-gate@v1
        with:
          # fail-on: high # blocking floor; default: critical
          # Optional today; required once license enforcement is enabled.
          license-key: ${{ secrets.LINEBREAK_LICENSE_KEY }}
          # Enables the AI code review; leave unset for dependency scan only.
          anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }}

Three steps to a protected repo

Enter your repository above to turn these into one-click links.

Steps 2 and 3 open GitHub settings pages that only repo admins can see. If GitHub shows a 404 there, ask the repo's owner for the admin role (or have them do these two steps).

1

Create the workflow file

Open GitHub's editor pre-filled with your snippet and press Commit: nothing to type.

2

Add your secrets

Only needed for the AI code review (the Pro part). Add LINEBREAK_LICENSE_KEY (hosted, on credits; we issue it during onboarding) or ANTHROPIC_API_KEY (your own key). The dependency scan runs free without either.

3

Require the check

Under branch protection, require the gate check. A check that can be ignored is a dashboard; required is what makes it a boundary.

Prefer the terminal?

One command does all three steps:

pip install linebreak-gate && linebreak-gate init

What a blocked pull request looks like

Real pull request blocked by the LineBreak Security Gate: required check failing and merge disabled

The comment updates in place on every push: fix the finding, or record a human override, and the check turns green. See it live: it is a real public PR.

Watch it run

Terminal recording: linebreak-gate scan blocks a critical CVE, the dependency is fixed, the second scan passes.

A real run: the scan blocks a critical CVE and exits non-zero, the pin gets fixed, the gate opens. Nothing here is mocked.

Signed approvals: Pro from $99/mo per team

Only a named human can override, on the record

AI never clears the gate. An override requires a reason and an approver, covers one exact finding only, and lives in your repo's audit trail: who accepted the risk, when, and why.

Dependency scanning is free: no key. The AI code review is Pro: unlock it with a LINEBREAK_LICENSE_KEY (hosted, on credits) or your own ANTHROPIC_API_KEY. License keys are issued by our team during onboarding. No self-serve checkout yet; request yours via Talk to us.