mirror of
https://github.com/SquidSec/SquidGate
synced 2026-08-09 12:22:48 +00:00
Demo only — hardcoded secret + injection / dangerous API patterns. See examples/README.md Co-authored-by: SquidSec Bot <bot@squidsec.local>
SquidGate language samples
A SquidSec Open Source Project · SquidOffense.com
Open a sample PR for your language to see SquidGate annotate real findings (hardcoded secrets, injection, dangerous APIs).
Each PR adds one small demo file under examples/<language>/ with intentional vulnerabilities. Do not copy these patterns into production code.
| # | Language | Sample PR |
|---|---|---|
| 1 | JavaScript | #2 |
| 2 | TypeScript | #3 |
| 3 | Python | #4 |
| 4 | Java | #5 |
| 5 | C# | #6 |
| 6 | Go | #7 |
| 7 | Rust | #8 |
| 8 | C++ | #9 |
| 9 | C | #10 |
| 10 | PHP | #11 |
| 11 | Ruby | #12 |
| 12 | Swift | #13 |
| 13 | Kotlin | #14 |
| 14 | Scala | #15 |
| 15 | Shell | #16 |
| 16 | Dart | #17 |
| 17 | PowerShell | #18 |
| 18 | SQL | #19 |
| 19 | Perl | #20 |
| 20 | Lua | #21 |
What you should see
- Check run named SquidGate
- Line annotations on the sample file
- PR comment summarizing findings
- Check failure when severity ≥
block_on(defaulthigh)
Use on your repo
- uses: SquidSec/SquidGate@v1
with:
llm-api-key: ${{ secrets.LLM_API_KEY }}
Pin an immutable build: SquidSec/SquidGate@v1.0.0-build.N — see Releases.