Zero to security coverage on every PR in three steps
Install once. No CI pipeline changes, no workflow YAML to maintain. Every pull request gets scanned automatically from that point forward.
Connect your repository
Install the Gritcadence GitHub App from the marketplace. Select the repositories you want scanned — you can add more later. The entire setup takes under 5 minutes.
Gritcadence requests the minimum permissions needed: read access to code and write access to pull request comments. No access to your build secrets, deployment keys, or repository settings.
Rules run on every PR
Every time a pull request is opened or updated, Gritcadence scans the changed code automatically. No manual trigger. No CI pipeline change required.
Scans cover 500+ built-in rules across Python, JavaScript/TypeScript, Go, Java, Ruby, and Rust — plus any custom YAML rules you've authored. Rules run against changed files only, not the full codebase, so scan times stay under a few seconds for typical PRs. Each finding includes a CWE ID, OWASP category, confidence level, and a suggested fix pattern.
Findings appear inline in your PR
Every finding becomes an inline PR review comment posted on the exact line where the issue was detected. Your reviewers see it in context — they don't have to leave GitHub, open another tool, or look up a finding ID.
Each comment includes the rule ID, severity, a plain-English explanation, and a suggested fix pattern. If a reviewer disagrees with a finding, they can suppress it inline with a justification — building an auditable record without leaving the review flow.
Common questions
.gritcadence.yaml config file in your repo root.Ready to connect your first repo?
Starter is free — up to 3 repos, 500+ built-in rules, no credit card required. First scan in under 5 minutes.