A live demo of the LineBreak Security Gate: the CI check that refuses to merge AI-written code carrying known vulnerabilities.
Pull request #1 was authored by an AI agent. It pins pyyaml to 5.3.1, a version with a known critical vulnerability (CVE-2020-14343, arbitrary code execution). The gate check failed, the check is required, and the merge button stays gray:
Nothing here is mocked. The gate ran in this repository's CI, found the CVE via OSV, and refused. It fails CLOSED: if the scanner itself crashes, the check fails too. The only way past it is a human override, scoped to that one package+version+CVE, committed to git with a name on it. No bot can approve that merge.
Free, no account:
uv tool install linebreak-gate
Guided first run (~10 min): https://www.linebreakapp.com/en/start
This repo's own main branch is protected by the same gate. Every change you see merged here passed it.
