mirror of
https://github.com/SquidSec/SquidGate
synced 2026-08-09 12:22:48 +00:00
- Product name SquidGate (check run, action, package, docs) - Config path .github/squidgate.yml - MIT © SquidSec; production README and docs - CONTRIBUTING, SECURITY, CHANGELOG - CI verifies dist/ is current
38 lines
849 B
Plaintext
38 lines
849 B
Plaintext
# SquidGate config — copy to .github/squidgate.yml
|
|
# https://github.com/SquidSec/SquidGate
|
|
version: 1
|
|
|
|
llm:
|
|
provider: openai # openai | anthropic | azure | google | custom
|
|
model: gpt-4o # or claude-*, gemini-*, grok-*, etc.
|
|
|
|
policy:
|
|
block_on: high # critical | high | medium | low | none
|
|
min_confidence: medium
|
|
categories:
|
|
secrets: true
|
|
injection: true
|
|
authn_authz: true
|
|
cryptography: true
|
|
insecure_deserialization: true
|
|
path_traversal: true
|
|
ssrf: true
|
|
xss: true
|
|
csrf: true
|
|
supply_chain: true
|
|
hardcoded_credentials: true
|
|
dangerous_functions: true
|
|
misconfiguration: true
|
|
custom_rules: []
|
|
|
|
context:
|
|
lines_before: 30
|
|
lines_after: 30
|
|
max_files: 50
|
|
max_diff_bytes: 500000
|
|
|
|
output:
|
|
comment_on_pr: true
|
|
annotate_lines: true
|
|
fail_on_error: true
|