Scan your staging environment on every push. Fail the build when security regresses.
Add .github/workflows/security.yml:
name: Security scan
on: push
jobs:
scan:
runs-on: ubuntu-latest
steps:
- run: npx -y @attackerview/[email protected] scan staging.example.com
env:
ATTACKERVIEW_API_KEY: ${{ secrets.ATTACKERVIEW_API_KEY }}The CLI triggers a scan, polls until it completes, and exits with code 1 if findings match the severity threshold, which fails the job. Create an API key from dashboard settings (Watchtower plan) and add it as a repository secret.
Flags such as --fail-on, --wait-timeout and --format json are documented on the CLI page.
Add --compare previous to diff against the last scan. The job fails only on new findings at or above the threshold, or on regressed findings:
name: Deploy gate
on:
push:
branches: [main]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- run: npx -y @attackerview/[email protected] scan staging.example.com --compare previous --fail-on critical,high
env:
ATTACKERVIEW_API_KEY: ${{ secrets.ATTACKERVIEW_API_KEY }}Without --compare, the job fails on any open finding matching --fail-on. With --compare previous, pre-existing issues you already triaged do not break builds.
For longer scans, trigger through the API and receive scan.completed via webhooks.