linebreak-gate
About
Fail-closed CI gate for AI-written code: blocks known CVEs and serves human-approved acceptance criteria to Claude Code/Cursor/Codex over MCP, read-only to the agent.
Explore
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
linebreak-gateCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
The CLI is a plain Python package with strict exit codes —0pass,1blocking findings,2tool/config error (fail closed: a scanner crash fails the pipeline, it is never a clean pass). Any CI that respects exit codes gets the same enforcement:
# .gitlab-ci.yml security-gate: image: python:3.11 script: - pip install linebreak-gate - curl -fsSL -o /usr/local/bin/osv-scanner "$(curl -fsSL https://api.github.com/repos/google/osv-scanner/releases/latest | python -c "import json,sys;print(next(a](https://pypi.org/project/linebreak-gate/)['browser_download_url'] for a in json.load(sys.stdin)['assets'] if a['name'].endswith('linux_amd64')))")" - chmod +x /usr/local/bin/osv-scanner - linebreak-gate scan - linebreak-gate report
Mark the job as required (noallow_failure) and protect the branch.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"linebreak-gate": {
"server": {
"command": "uvx",
"args": [
"linebreak-gate",
"mcp"
]
}
}
}
}
McpServers
{
"server": {
"command": "uvx",
"args": [
"linebreak-gate",
"mcp"
]
}
}
Transport
"stdio"
Package
"linebreak-gate"
Registry
"pypi"
A real pull request, blocked for real: the gate is arequired check, so the merge button goes gray until the CVE is fixed or a named human records an override.
See it live — a public PR you can open right now →
A real recording, no mock: the scan blocks a critical CVE fail-closed, the pin gets fixed, the gate opens.
The spec loop: a named human approves the criteria,checkblocks until the manual criterion carries a sign-off, then everything passes.
Blocks merges that carry known vulnerabilities. One tool, two detectors —dependency scanning is free; the AI review is the Pro upgrade:
The gateblocks and can propose; it never auto-clears on an agent's say-so. A human approves the fix or records an override — with a reason and an approver — in a git-committed audit file.
This is the same scanner core that powers the rest of LineBreak's in-product security gate (the desktop backend imports this package), but it is fully standalone: a team that has never touched anything else from LineBreak can add the gate to their repo and get real enforcement.
Contributing & license.This repo is the published source of[linebreak-gate(Apache-2.0): every release lands here and on PyPI from our CI, and every change passed our own gate first — CVE scan and human-approved criteria, the same discipline we sell. Bug reports and feature requests: open an issue or discussion here; we read everything. Direct PRs to this repo can't be merged (releases flow through our review pipeline), so start with an issue and we'll take it from there.
# .github/workflows/security-gate.yml name: Security gate on: pull_request: permissions: contents: read pull-requests: write # for the summary comment jobs: gate: runs-on: ubuntu-latest steps: - uses: actions/checkout@v5 - uses: Baktun-Studio/linebreak-gate@v1 with: # fail-on: high # blocking floor; default: critical # Optional today; required once license enforcement is enabled. license-key: ${{ secrets.LINEBREAK_LICENSE_KEY }} # Enables the AI code review; leave unset for dependency scan only. anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }}
The action runslinebreak-gate scan, always runsreport, postsonePR comment (updated in place on every push, never spammed), uploads the JSON report + audit artifacts as a workflow artifact, and fails the check per the scan's exit code.
Make it a real boundary: require the check
A CI job that can be ignored is a dashboard, not a gate. In your repo:
Settings → Branches → Branch protection rules → your default branch → "Require status checks to pass before merging"→ add thegatejob (the name of the job that runs this action). From then on a PR carrying a critical CVE cannot be merged through the GitHub UI.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



