Shift-left · CI/CD

CI Gate, SARIF & Public API

Run heimdallX from your pipeline: a scan per build, SARIF into code scanning, an SBOM per release — and a gate that breaks the build only on what was demonstrated.

A finding that arrives after the deploy is a ticket; one that arrives in the pull request is a fix. A per-workspace CI key authenticates a headless runner that enqueues a scan, polls for the result and receives SARIF 2.1.0 for GitHub or GitLab code scanning, a CycloneDX SBOM for the release, and a gate decision with reasons. Because every finding carries its verification tier, the gate can be set to fail only on the demonstrated tier — so a build never breaks on a heuristic. Everything the runner does is in the public OpenAPI specification; nothing is reachable only through the UI.

A gate you can trust

Severity thresholds are table stakes; the switch that matters is failOnVerified. A version-matched CVE and a reflected payload should not have the same power to stop a release, and the tiers are what make that distinction enforceable in a pipeline.

Standard formats, standard tooling

SARIF lands in the code-scanning tab your engineers already read. The SBOM is CycloneDX 1.5 with development dependencies marked rather than dropped, and a capped inventory says so inside the document.

API-first, key-scoped

CI keys are stored only as hashes and scoped to one workspace; the same API drives assets, scans, credentials for authenticated crawls, exports and telemetry ingestion. Reference workflow templates live in the repository.

How it works

1

Key

Mint a workspace CI key; it is hashed at rest.

2

Scan

The pipeline enqueues a scan and polls the result.

3

Emit

SARIF to code scanning, SBOM to the release.

4

Gate

Pass or fail — with reasons, on the tier you chose.

Pipeline in action
$ curl -X POST /api/ci/scan -H 'Authorization: Bearer hxci_…' -d @scan.json
→ scan 7f3a queued · 41s · 9 findings (2 proven)
→ GET /ci/scan/7f3a → sarif + gate · /sbom → 48 components
✗ gate: FAIL — failOnVerified · proven reflected XSS on /search?q=

Put it to work

Run your first scan in under two minutes. Free, no credit card, real findings.

Launch heimdallX
CI Gate, SARIF & Public API — heimdallX