Quickstart
This gets dagsec reporting on your pull requests in about two minutes.
1. Sign in
Go to app.dagsec.net and sign in with GitHub. dagsec asks only for your public profile and email; it gets no access to your repositories.
2. Pick how pull requests are scanned
Easiest: the GitHub App
Open Integrations in the dashboard and click Install on GitHub. Choose the repositories. That's it: the next pull request gets a dagsec check and comment. No workflow file, no secret. More about the GitHub App.
If your code must never leave your own CI, use the Action instead:
- In the dashboard, open API keys and create a key. Copy it; it is shown once.
- In your repository, go to Settings → Secrets and variables → Actions and add a secret named
DAGSEC_API_KEY. - Add
.github/workflows/dagsec.yml:
name: dagsec
on: pull_request
permissions:
contents: read
pull-requests: write
id-token: write
jobs:
dagsec:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: hasanerman/dagsec-action@v1
with:
api-key: ${{ secrets.DAGSEC_API_KEY }}On GitLab, see GitLab CI.
3. Open a pull request
The dagsec check runs and comments with what it found. If it fails, the comment says why and what to do: rotate a credential, upgrade to a named version, or replace a package.
4. Protect your AI coding agent (optional)
In Claude Code:
/plugin marketplace add hasanerman/dagsec-claude
/plugin install dagsec@dagsecPaste your API key when asked. From now on, an install of a package that doesn't exist, or of a version with critical or high vulnerabilities, is stopped and Claude is told which version to use. Cursor and Gemini CLI work too: see Cursor and Gemini CLI.
Next steps
- Turn on vulnerability alerts to get an email when a new advisory affects a version you use.
- Add a license policy with
.dagsec.toml. - Mark false positives in
.dagsecignore.