CI/CD Integration

Run Launchsafe in any CI/CD pipeline

Edit on GitHub

Launchsafe runs in headless mode for automated pipelines.

Headless Mode

Use the -n or --non-interactive flag:

launchsafe -n --target ./app --scan-mode quick

For pull-request style CI runs, Launchsafe automatically scopes quick scans to changed files. You can force this behavior and set a base ref explicitly:

launchsafe -n --target ./app --scan-mode quick --scope-mode diff --diff-base origin/main

Exit Codes

CodeMeaning
0No vulnerabilities found
1Execution error
2Vulnerabilities found

GitLab CI

.gitlab-ci.yml
security-scan:
  image: docker:latest
  services:
    - docker:dind
  variables:
    LAUNCHSAFE_LLM: $LAUNCHSAFE_LLM
    LLM_API_KEY: $LLM_API_KEY
  script:
    - curl -sSL https://launchsafe.ai/install | bash
    - launchsafe -n -t ./ --scan-mode quick

Jenkins

Jenkinsfile
pipeline {
    agent any
    environment {
        LAUNCHSAFE_LLM = credentials('launchsafe-llm')
        LLM_API_KEY = credentials('llm-api-key')
    }
    stages {
        stage('Security Scan') {
            steps {
                sh 'curl -sSL https://launchsafe.ai/install | bash'
                sh 'launchsafe -n -t ./ --scan-mode quick'
            }
        }
    }
}

CircleCI

.circleci/config.yml
version: 2.1
jobs:
  security-scan:
    docker:
      - image: cimg/base:current
    steps:
      - checkout
      - setup_remote_docker
      - run:
          name: Install Launchsafe
          command: curl -sSL https://launchsafe.ai/install | bash
      - run:
          name: Run Scan
          command: launchsafe -n -t ./ --scan-mode quick

On this page