CI Gate, SARIF & Public API
Run heimdallX from your pipeline: a scan per build, SARIF into code scanning, an SBOM per release — and a gate that breaks the build only on what was demonstrated.
A finding that arrives after the deploy is a ticket; one that arrives in the pull request is a fix. A per-workspace CI key authenticates a headless runner that enqueues a scan, polls for the result and receives SARIF 2.1.0 for GitHub or GitLab code scanning, a CycloneDX SBOM for the release, and a gate decision with reasons. Because every finding carries its verification tier, the gate can be set to fail only on the demonstrated tier — so a build never breaks on a heuristic. Everything the runner does is in the public OpenAPI specification; nothing is reachable only through the UI.
A gate you can trust
Severity thresholds are table stakes; the switch that matters is failOnVerified. A version-matched CVE and a reflected payload should not have the same power to stop a release, and the tiers are what make that distinction enforceable in a pipeline.
Standard formats, standard tooling
SARIF lands in the code-scanning tab your engineers already read. The SBOM is CycloneDX 1.5 with development dependencies marked rather than dropped, and a capped inventory says so inside the document.
API-first, key-scoped
CI keys are stored only as hashes and scoped to one workspace; the same API drives assets, scans, credentials for authenticated crawls, exports and telemetry ingestion. Reference workflow templates live in the repository.
How it works
Key
Mint a workspace CI key; it is hashed at rest.
Scan
The pipeline enqueues a scan and polls the result.
Emit
SARIF to code scanning, SBOM to the release.
Gate
Pass or fail — with reasons, on the tier you chose.
$ curl -X POST /api/ci/scan -H 'Authorization: Bearer hxci_…' -d @scan.json→ scan 7f3a queued · 41s · 9 findings (2 proven)→ GET /ci/scan/7f3a → sarif + gate · /sbom → 48 components✗ gate: FAIL — failOnVerified · proven reflected XSS on /search?q=
Put it to work
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX