GGateTest
v1.61.1122 modulesbetagithub · gitlab · circleci · gluecron

122 checks, one CI gate.
Fails on the diff, not the backlog.

Deterministic static analysis on every push, scored against a baseline file you commit, so the job fails only on new findings. Every report lists what was not checked. Precision is measured nightly on 19 pinned third-party repositories and published, misses included.

Install GluecronInstall the GitHub AppQuickstart, four stepsnpx -p @gatetest/cli gatetest --suite quick
gatetest --suite quickrunning
your-org/your-repo·pull request #248Checks
GateTest Quality Gate — queued
build — 41s
Terminal output captured 2026-09-22 on reliability-corpus/known-bad/sqli-string-concat, exit code 1. The comment and fix PR are the same finding as the fix tiers render it.
122
modules in the gate
site-stats.json · gatetest --list
19
pinned third-party repositories in the corpus
precision.json · nightly
5
of them with zero blocking findings
precision.json · ceilings only ratchet down
12,040
tests passing on our own repo, every commit
site-stats.json · scripts/run-tests.js
what your team receives

Three artifacts. Nothing to log in to.

01

Every push sets a commit status

The App or the Action runs the deterministic checks on the diff, scores them against the committed baseline, and writes one status. A blocking finding means exit 1 and a red check. Nothing else in your pipeline changes.

http
POST /repos/your-org/your-repo/statuses/9f2c1a7
{
  "state": "failure",
  "context": "GateTest Quality Gate",
  "description": "2 blocking findings in this diff · 5 checks not run",
  "target_url": "https://gatetest.io/scan/scn_4b1e…"
}
02

One comment names the findings and what was not run

Line-attributed, with the exact ignore reply beside each finding. Checks that could not run are listed, never silently counted as passed. Baselined findings stay visible and stay out of the verdict.

markdown
## 2 blocking findings in this diff

| File | Finding | Reply to ignore |
| --- | --- | --- |
| src/handler.js:12 | `q` from request input reaches a `sql-query` sink | `@gatetest ignore crossFileTaint@src/handler.js` |
| src/handler.js:20 | `result` from request input reaches a `sql-query` sink | same |

**Not checked:** lint (no ESLint config), dependencies (no lockfile).
Baseline: .gatetest/baseline.json @ 3 findings — none of them counted here.
03

On the fix tiers, a pull request with the patch and its test

A model writes the patch; the gate re-runs on it; a regression test is added; a second model reviews the diff. You review and merge, or reply to reject. Pricing is per run, not per seat.

markdown
## fix: parameterise the SQL in handler.js

- src/handler.js: two queries rewritten with placeholders
- tests/handler.sql.test.js: regression test for both sinks (added)
- Gate re-run on this patch: 0 blocking · 3 warnings
- Second-model review: approved, no scope creep

Cost of this fix: 38 s · ~$0.02 API
measured on code we did not write

A gate that blocks clean code gets uninstalled. So the numbers are public.

Every push runs the full suite on 19 pinned commits of repositories we do not control. Each has a ceiling that only goes down. Hover a row for what that repository taught the rules.

django: 46 blocking, ceiling 46 — Python at scale — the ORM builds SQL by string in django/db, which is the one place that is the job; 74 of 76 "secrets" were test fixtures before the identifier-keyed rules learned about test pathsdjango46/46rails: 34 blocking, ceiling 34 — Ruby at scale — instance_eval in the routes loader, backtick-quoted words in error messages that a naive shell-interp rule read as commandsrails34/34hono: 14 blocking, ceiling 14 — every crossFileTaint finding here was false: c.req.query() read as SQL, RegExp.exec() as command exec; 2026-09-05 importCycle type-only elision: the four import cycles it blocked on read every binding inside function bodies — deferred, now a warning — ceiling ratchets downhono14/14prisma: 12 blocking, ceiling 12 — pnpm monorepo, packages/** nesting, a SQL toolkit that builds SQL by design — first contact 90 blocking: `${STORAGE_TABLE}` constants as injection, seeding loops in test/ as N+1, teardown catches as swallows, tsconfig/ and turbo.json as invalid JSON, `base.sha` as shell injection, an un-runnable test:integration as failing tests; what remains is DDL with a computed database name, three import cycles, telemetry catches and a dev-tool page without a description; 2026-09-05 importCycle type-only elision: the three import cycles it blocked on read their bindings in parameter defaults and method bodies — deferred, now a warning — ceiling ratchets downprisma12/12nest: 9 blocking, ceiling 9 — TypeScript monorepo (npm workspaces) with an integration/ e2e tree and sample apps — first contact 39 blocking: a logger class told it uses console, tsconfig flags as build verdicts, mongodb://localhost fixtures as secrets, `.catch(() => {})` on a stored promise the caller awaits; what remains is six `reduce(async …)` in the e2e app, two npm-audit advisories and one committed PKCS#8 keynest9/9spring-petclinic: 8 blocking, ceiling 8 — Java + Thymeleaf templates + a k8s manifest; the reference Spring appspring-petclinic8/8ktor: 7 blocking, ceiling 7 — Kotlin — first contact 21 blocking, 14 of them a test.html under test-resources/ scored as a public page, plus a Gradle compile failure in our environment reported as failing tests; what remains is six real TODO() stubs and one third-party workflow on @mainktor7/7trpc: 7 blocking, ceiling 7 — pnpm monorepo with members under examples/* and www — first contact 33 blocking: build configs and a CLI told they log to console, an OG-image generator scored as a web page, an Algolia search key as a secret, ternary env fallbacks as hardcoded URLs; what remains is four <img> without alt, a real import cycle, a silent connect in a constructor and `${{ github.event.release.tag_name }}` in a shell; 2026-09-05 importCycle type-only elision: its one import cycle ran through two `import { type X }` edges — elided, never a cycle in emitted JS — ceiling ratchets downtrpc7/7axum: 5 blocking, ceiling 5 — Rust — first contact 28 blocking: todo!()/unimplemented!() inside #[cfg(test)] modules, dtolnay/rust-toolchain@stable read as a branch pin; what remains is third-party actions on @master and one real unimplemented!()axum5/5cleanarchitecture: 4 blocking, ceiling 4 — C# + Angular + React — first contact 39 blocking, 26 of them SEO/a11y rules on the two SPA index.html shells; what remains is real: strict:false, a committed .env, unlabeled inputs, log-and-eat catches in a React componentcleanarchitecture4/4laravel: 4 blocking, ceiling 4 — PHP — first contact 28 blocking, 23 of them `$redis->eval($lua)` read as PHP eval(); what remains is real eval(var_export()) in the config cache and an unguarded rm -rf in a release scriptlaravel4/4fastify: 3 blocking, ceiling 3 — large plugin-oriented server; exercises the auth and route grammarsfastify3/3flask: 2 blocking, ceiling 2 — Python — proves the non-JS rules are held to the same barflask2/2zod: 2 blocking, ceiling 2 — monorepo with a docs site and benchmarks; was the worst case at 50, of which 33 were errorSwallow — 23 in benchmark harnesses, 7 the parsing library's coerce-then-check idiom (2026-09-04)zod2/2apollo-server: 0 blocking, ceiling 0 — npm-workspaces monorepo with a docs site — first contact 4 blocking: a CA bundle read as a private key, a README link the resolver could not follow, a destructured parameter the scope harvester missed; nothing remainsapollo-server0/0express: 0 blocking, ceiling 0 — the most-depended-on Node package there is; the canonical clean controlexpress0/0gin: 0 blocking, ceiling 0 — Go — the ignored-error idiom the go module could not see until 2026-09-04gin0/0got: 0 blocking, ceiling 0 — TypeScript HTTP client with a benchmark/ tree — a known scope trapgot0/0vapor: 0 blocking, ceiling 0 — Swift — first contact 6 blocking: its own reusable workflows on @main and README section gaps; what remains is a *.key file the .gitignore does not covervapor0/0
0 blockingblocking at or under the ceilingceiling5 of 19 clean · measured 2026-10-01 · engine 1.61.1
Every repository, every commit, every ceiling
one engine

Where it runs

WhereIdentifierCostOutput
GitHub Appgithub.com/apps/gatetest-hqfree gate on every pushcommit status, PR comment
GitHub Actionuses: crclabs-hq/GateTest@v1free, public and privategate, SARIF, JUnit, baseline
Terminalnpx -p @gatetest/cli gatetest --suite quickfree, offline, MITverdict, exit code, JSON
VS Code / Open VSXGateTestHQ.gatetestfree, nothing leaves the machinefindings in the Problems panel
AI agent (MCP)npx @gatetest/mcp-serverfree on your own keys24 tools: scan, explain, fix, run tests, verify
GitLab / CircleCIgatetest --ci-init gitlab | circlecifreea complete pipeline file
Any live sitegatetest --crawl https://example.comfree preview, no repoheaders, TLS, links, a11y, SEO per page
pay per run

Pricing

TierPriceBillingScopeWhat you get
Quick Scan$29one-time · repositorysyntax, lint, secrets, codeQuality4 modules — syntax, linting, secrets, code quality
Full Scan$99one-time · repositoryall-applicableThe full engine — every module that applies to a repository: security, supply chain, auth, CI hardening, structure, AI review, and more. (Live-URL and WordPress modules need a deployed site; mutation + chaos ship via the GitHub Action.) Scan-only (no auto-fix — that ships at Scan + Fix $199 and above).
Scan + Fix$199one-time · repositoryall-applicable+pair-review+architectureEverything in Full Scan, plus a second-agent pair-review critique on every fix (correctness/completeness/readability/test-coverage rubric) and a separate architecture-annotator report on codebase-shape design observations. Same PR, deeper deliverable.
Forensic Scan$399one-time · repositoryall-applicable+forensic-stackEverything in Scan + Fix, PLUS: real AI diagnosis on every finding (no templated snippets), cross-finding attack-chain correlation (textbook session-forgery / supply-chain vectors no per-finding scanner can see), board-ready CISO report (findings mapped to OWASP Top 10 and CIS Controls v8, with a 30/60/90-day remediation plan), and a CTO-readable executive summary report. Mutation testing and chaos / fuzz pass are also available via the GitHub Action (mutation: true / chaos: true) — they need a CI runner so they ship wherever your CI runs.
Website Scan — Full Report$29one-time · live siteweb-suiteUnlocks every finding on the website scanner: full issue list, plain-English fix instructions, and the complete health-score breakdown for your site.
WordPress Health Check — Full Report$19one-time · live sitewp-suiteUnlocks the full WordPress health report: every finding, plugin/theme risk detail, and plain-English fix instructions for your site.
Continuous$49/mosubscriptionsubscription-continuousScan every push across EVERY repo in your org — one flat $49/mo, no per-seat, no per-repo (org-flat since 2026-07-23). Unlimited deterministic push scans, plus a monthly AI-review allowance shared across the org that escalates pushes to the deeper full-suite scan while budget remains. Fix PRs are a per-scan upsell. Cancel anytime.
GateTest MCP$29/mosubscriptionsubscription-mcpHosted MCP access — use GateTest from web and mobile AI clients and locked-down machines with no local install, plus hosted scan history. The LOCAL MCP server is free with every tool ungated (2026-07-23) — this tier is for when you can't run npx. API key delivered by email when checkout completes. Cancel anytime.
Enterprisecontactinvoicedsame enginecustom scan volume, raised AI-review budget, priority support, invoicing on your terms

Charged at checkout, no seats, no minimum. The engine is open source and free to run yourself; hosted runs are what is billed.

before you install

The questions engineers ask first

Will it block my whole backlog on day one?
No. `gatetest --baseline` snapshots every current finding into .gatetest/baseline.json, you commit it, and the gate fails only on findings not in it. Baselined findings stay visible in every report and are counted per file, so a new one cannot hide behind an old one.
How do I know the rules are not over-firing?
The corpus above. Every push scans 20 pinned commits of repositories we do not control; each has a ceiling that only ratchets down, and the numbers are published including the bad ones. A rule that starts over-firing on express or Django turns our CI red before yours.
What does the model actually do?
Nothing in the default scan; that is deterministic and reproducible. On the fix tiers a model writes a patch for a located finding, the gate re-runs on the patch, a regression test is added, and a second model reviews the diff. The CLI and local MCP server run on your own key.
What is reported when something could not run?
It says so, in the terminal, the PR comment and the JSON: 'not checked' with the reason. A pass from silence is treated as the worst bug in this codebase.
Where does my code go?
The CLI, the Action, the editor extension and the local MCP server run where you run them; nothing is uploaded. Hosted scans read the repository over HTTPS on our box and keep the report for the share window. The GitHub App uses scoped permissions and short-lived installation tokens; every webhook is HMAC-verified and fails closed.