Skip to content

Quickstart ​

This gets dagsec reporting on your pull requests in about two minutes.

1. Sign in ​

Go to app.dagsec.net and sign in with GitHub. dagsec asks only for your public profile and email; it gets no access to your repositories.

2. Pick how pull requests are scanned ​

Easiest: the GitHub App

Open Integrations in the dashboard and click Install on GitHub. Choose the repositories. That's it: the next pull request gets a dagsec check and comment. No workflow file, no secret. More about the GitHub App.

If your code must never leave your own CI, use the Action instead:

  1. In the dashboard, open API keys and create a key. Copy it; it is shown once.
  2. In your repository, go to Settings → Secrets and variables → Actions and add a secret named DAGSEC_API_KEY.
  3. Add .github/workflows/dagsec.yml:
yaml
name: dagsec
on: pull_request
permissions:
  contents: read
  pull-requests: write
  id-token: write
jobs:
  dagsec:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      - uses: hasanerman/dagsec-action@v1
        with:
          api-key: ${{ secrets.DAGSEC_API_KEY }}

On GitLab, see GitLab CI.

3. Open a pull request ​

The dagsec check runs and comments with what it found. If it fails, the comment says why and what to do: rotate a credential, upgrade to a named version, or replace a package.

4. Protect your AI coding agent (optional) ​

In Claude Code:

/plugin marketplace add hasanerman/dagsec-claude
/plugin install dagsec@dagsec

Paste your API key when asked. From now on, an install of a package that doesn't exist, or of a version with critical or high vulnerabilities, is stopped and Claude is told which version to use. Cursor and Gemini CLI work too: see Cursor and Gemini CLI.

Next steps ​