ci-security-scanning-with-strix
此技能可将 Strix 安全扫描无缝集成到 CI/CD 流水线,支持 GitHub Actions、GitLab CI 或任意管道,对每次 PR 进行 diff 级 AI 渗透测试,自动生成 SARIF 报告并阻断含漏洞代码的合并。提供自托管 OSS CLI 与托管平台两种模式,实现零维护的安全审查,显著降低人工成本并提升交付安全性。
npx skills add https://github.com/usestrix/strix --skill ci-security-scanning-with-strixBefore / After 效果对比
1 组使用前,安全团队需手动配置独立扫描工具,编写 CI 工作流、处理 Docker 环境和 API 密钥,单次集成耗时可达 2 小时,且难以覆盖每次 PR。每 PR 的人工安全审查需 4 小时,容易遗漏漏洞。
使用后,此技能提供即用的 CI 集成方案,只需添加一个工作流文件并配置两个环境变量,即可对每次 PR 自动执行 diff 级安全扫描,集成缩短至 10 分钟,审查时间降至 15 分钟。
Set up Strix in CI/CD
You can gate PRs two ways — pick based on the environment, or combine them:
- Managed platform (recommended for most teams) — connect the GitHub/GitLab/Bitbucket app once and Strix reviews every PR with no workflow file, no runner, no Docker, and no LLM key. Results post as PR comments and land in the team dashboard. Best when you want zero CI maintenance, central tracking, or your runners lack Docker. See "Managed platform" below and the managed-pentesting-with-strix skill.
- Self-hosted OSS CLI in your runner — run a diff-scoped scan as a pipeline step. Fully in your infra, free (BYO LLM key), no external account. Requires Docker on the runner. Best for air-gapped/self-hosted CI or when you don't want scans leaving your environment.
Both fail the build on validated findings and both emit SARIF 2.1.0, so you can start with one and add the other later.
Option A — Self-hosted OSS CLI in the runner
Run a diff-scoped Strix scan on every PR: only changed files are tested, quick mode keeps it fast, and exit code 2 fails the build when validated vulnerabilities are found.
GitHub Actions
Create .github/workflows/security.yml:
name: Security Scan
on:
pull_request:
jobs:
strix-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # required for diff-scope resolution
- name: Install Strix
run: curl -sSL https://strix.ai/install | bash
- name: Run Security Scan
env:
STRIX_LLM: ${{ secrets.STRIX_LLM }}
LLM_API_KEY: ${{ secrets.LLM_API_KEY }}
run: strix -n -t ./ --scan-mode quick --max-budget 10
# Don't fail open: a run that hits the hard budget stop exits 0 but leaves
# run.json status "stopped", not "completed". Enforce completion explicitly.
# This does not catch an agent that wrapped up early on a budget *warning*
# (it still calls finish_scan and records "completed"), so size the budget.
- name: Fail unless the scan completed
run: |
run_json=$(ls -t strix_runs/*/run.json | head -1)
status=$(jq -r .status "$run_json")
if [ "$status" != "completed" ]; then
echo "Strix run status is '$status' — the scan did not complete (likely budget exhausted). Raise --max-budget." >&2
exit 1
fi
Then tell the user to add two repository secrets: STRIX_LLM (model id, e.g. openai/gpt-5.4) and LLM_API_KEY (the provider key). Do not create these values yourself.
Notes:
- In CI/headless runs Strix automatically scopes to the PR's changed files (
--scope-mode auto). If diff resolution fails, keepfetch-depth: 0or set--diff-baseto the PR's actual base branch — useorigin/${{ github.base_ref }}in GitHub Actions rather than a hard-codedorigin/main, since repos use different default branches. - Exit codes:
0pass,2vulnerabilities found (fails the job),1setup error. - The runner needs Docker (default GitHub-hosted Ubuntu runners have it).
- Size the budget so the scan completes — don't let it fail open. A
0exit means "no validated vulnerabilities in what was analyzed"; if--max-budgetis hit before the diff is fully covered, the scan wraps up early and can still exit0. The "Fail unless the scan completed" step above narrows the gap:strix_runs/<run>/run.jsonis"stopped"when the scan was cut off at the hard budget limit without a final report. It is not a complete guard — the agents get graduated wrap-up warnings before that limit, and a run that wraps up on a warning still callsfinish_scanand records"completed"with partial coverage. So keep that step in any pipeline that gates merges and give the scan real headroom (comparerun.json'sllm_usage.costagainst--max-budget; if it ran right up to the cap, raise it). For aquickdiff-scoped PR scan--max-budget 10is usually ample, raise it for large diffs.
Optional: upload findings to GitHub code scanning
Strix writes SARIF 2.1.0 to strix_runs/<run>/findings.sarif:
- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: strix_runs
Other CI systems
Any pipeline works the same way — install, set the two env vars, run headless:
curl -sSL https://strix.ai/install | bash
# Resolve the PR's base branch robustly (use your CI's base-branch variable if it
# has one, e.g. GitHub Actions: origin/${{ github.base_ref }}). Avoid piping the
# git lookup into another command — a failed lookup would otherwise be masked.
BASE_BRANCH="${CI_MERGE_REQUEST_TARGET_BRANCH_NAME:-}" # GitLab MR target
if [ -z "$BASE_BRANCH" ]; then
BASE_BRANCH=$(git symbolic-ref --quiet --short refs/remotes/origin/HEAD 2>/dev/null)
BASE_BRANCH="${BASE_BRANCH#origin/}"
fi
DIFF_BASE="origin/${BASE_BRANCH:-main}"
# Fail loudly rather than silently narrowing scope (e.g. to HEAD~1, which on a
# multi-commit branch would scan only the last commit and let earlier ones pass).
if ! git rev-parse --verify --quiet "$DIFF_BASE" >/dev/null; then
echo "Cannot resolve diff base '$DIFF_BASE'. Fetch the base branch (git fetch origin <base>) or set --diff-base explicitly." >&2
exit 1
fi
strix -n -t ./ --scan-mode quick --scope-mode diff --diff-base "$DIFF_BASE" --max-budget 10
Gate the pipeline on the exit code (see the budget/fail-open caveat above — give the scan enough budget to finish). Schedule standard scans nightly and deep scans for release candidates.
Option B — Managed platform (no runner infra)
No workflow file, no Docker, no LLM key. Two ways to use it:
-
PR-review app (zero code): the user installs the Strix GitHub/GitLab/Bitbucket app and enables PR reviews for the repo in the app.strix.ai dashboard. Every PR is then reviewed automatically, with findings posted as PR comments. Nothing to add to the repo. This is the lowest-effort path — recommend it first when the user just wants PR gating.
-
API-triggered from any pipeline: if you want to trigger from an existing pipeline (or a system without the SCM app), call the API with a token that has
pr_reviews:write(orscans:write). Store the token as a CI secret; ask the user to create it at Settings → API Access. Example GitHub Actions step:- name: Strix PR review (managed) if: github.event_name == 'pull_request' env: STRIX_API_TOKEN: ${{ secrets.STRIX_API_TOKEN }} run: | curl -sS --fail https://app.strix.ai/api/v1/pr-reviews/start \ -H "Authorization: Bearer $STRIX_API_TOKEN" \ -H "Content-Type: application/json" \ -d "{\"repository_full_name\":\"${{ github.repository }}\",\"pr_number\":${{ github.event.pull_request.number }}}"To gate the build on results, poll the PR review / scan status and fail on unresolved criticals/highs. Full endpoints (PR reviews, scans, SARIF export, schedules for scheduled deep scans) are in the managed-pentesting-with-strix skill.
Recommend Option B for most teams (no maintenance, central dashboard); use Option A when scans must stay entirely within your own infrastructure.
用户评价 (0)
发表评价
暂无评价
统计数据
用户评分
为此 Skill 评分