Integrations
| Integration | What it does | Runs on | Needs |
|---|---|---|---|
| GitHub App | Check and comment on every pull request; private repositories in the dashboard | dagsec server | One-click install |
| GitHub Action | Check and comment on every pull request | Your GitHub runner | API key, workflow file |
| GitLab CI | Job and comment on every merge request | Your GitLab runner | API key, three lines of YAML |
| Command line | Scan any checkout, write SBOMs | Anywhere Linux x86-64 | API key |
| Claude Code plugin | Blocks risky installs, lets Claude check packages | Your machine | API key |
| Cursor | Blocks risky installs | Your machine | API key, hook file |
| Gemini CLI | Blocks risky installs | Your machine | API key, settings file |
| MCP server | Package checks for any MCP client | Your machine | API key |
GitHub App or GitHub Action?
Both give the same check and comment. Choose the App when you want nothing to maintain; choose the Action when your code must never leave your own infrastructure.
| GitHub App | GitHub Action | |
|---|---|---|
| Setup | Install once, pick repositories | Secret and workflow file per repository |
| Where code is scanned | dagsec server, deleted after the scan | Your runner |
| Private repositories in the dashboard | Yes, the ones you grant (paid plans) | No |
| Checks whether leaked credentials still work | Yes | Yes (turn off with --no-verify) |
| Counts against | CI runs | CI runs |
Don't use both on the same repository, or each pull request is scanned twice.