Lightlines
Catalogue
Sign in
By usestrix

ci-security-scanning-with-strix

usestrix

Block vulnerable changes before merge.

application security

What it does

Add Strix security scanning to CI/CD pipelines so pull requests receive diff-scoped vulnerability checks before merging.

When to use it

Use when adding security scanning, SAST/DAST, pentesting, vulnerability checks, or automated security review to a CI pipeline, pre-merge gate, or PR workflow.

How to use it

Give it a project and a request for CI security scanning; it adds a Strix-based pipeline configuration and merge-gating checks.

What you provide

  • security scanning
  • CI pipeline
  • An existing project

Uses


Access · 6

This skill

GitHub/GitLab/Bitbucket pull requests

Write

Posts PR security findings (irreversible)

Strix cloud scans

Write

Uploads source for cloud review

GitHub code scanning

Write

Uploads SARIF findings

Strix managed repository configuration

Read

Reads repository configuration

Good to know

  • cannot be undone: GitHub/GitLab/Bitbucket pull requests

What you need · 3

The self-hosted scan reads the provider key from the LLM_API_KEY environment variable, together with STRIX_LLM.

Docker must be available on the self-hosted CI runner; this is not needed for the managed platform path.

A Strix managed-platform account and connected source-control app are needed for the managed path; the self-hosted path requires no external account.


About this skill

Visibility
Public
Repository
usestrix/strix
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
1