mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-08-14 13:40:23 +02:00
feat: PR security gate, @neurosploit bot, richer NL REPL (#39)
GitHub automation - integrations: github_set_status (commit status), github_pr_review (REQUEST_CHANGES/APPROVE), github_pr_head_sha, and a shared severity gate (severity_rank / worst_confirmed_rank / gate_trips — confirmed findings only). - `neurosploit pr --fail-on <critical|high|medium|low>`: on a confirmed finding at/above the threshold, sets a failing `neurosploit/security` commit status, posts a REQUEST_CHANGES review, and exits 2 so a CI check fails — branch protection then blocks the merge. - Two ready GitHub Actions: neurosploit-pr-gate.yml (review + block every PR) and neurosploit-mention.yml (writers comment @neurosploit <text> to trigger a scan; any language; URL → black-box, else PR review). Natural-language REPL - Intent now also parses spoken toggles/knobs across PT/EN/ES: Burp/proxy, browser/MCP, subscription, "N votos/votes", recon depth (number or quick/deep/exhaustive), plus stop verbs. handle_nl returns the follow-up command (/run or /stop). Docs: README trimmed to features (version changelog stays in RELEASE.md), new automations documented in README + TUTORIAL-INTEGRATION. Tests: gate (3), NL toggles/stop (added). All green. Claude-Session: https://claude.ai/code/session_018BGLy4j5qsqqid6CoovowC Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
21a62c95e5
commit
3786d7c559
+44
-2
@@ -1,7 +1,8 @@
|
||||
# NeuroSploit — Integrations Setup Guide (v3.5.3)
|
||||
# NeuroSploit — Integrations Setup Guide
|
||||
|
||||
Connect NeuroSploit to **GitHub**, **GitLab** and **Jira** so it can review private
|
||||
repositories and Pull Requests, watch branches for new code, and file a Jira
|
||||
repositories and Pull Requests, **gate merges** on severe findings, watch branches
|
||||
for new code, run from a **`@neurosploit`** comment, and file a Jira
|
||||
**card per vulnerability**.
|
||||
|
||||
> ⚠️ **Authorized testing only.** Use integrations against code/projects you own or
|
||||
@@ -100,10 +101,51 @@ neurosploit integrations enable github
|
||||
```
|
||||
It polls the branch tip via the GitHub API and runs a white-box review whenever
|
||||
the SHA changes (Ctrl-C to stop).
|
||||
- **Gate a Pull Request** — block the merge when a confirmed finding is severe:
|
||||
```bash
|
||||
neurosploit pr myorg/private-app 128 \
|
||||
--model anthropic:claude-opus-4-8 --comment --fail-on critical
|
||||
```
|
||||
`--fail-on <critical|high|medium|low>` does three things when a **confirmed**
|
||||
finding is at/above the threshold: the CLI **exits non-zero** (so a CI check
|
||||
fails), it sets a **`neurosploit/security` commit status** of `failure` on the
|
||||
PR head, and it submits a **REQUEST_CHANGES** review. `needs-review` findings
|
||||
never trip the gate — only confirmed ones do.
|
||||
|
||||
**GitHub Enterprise:** `/integrations setup github` and set the API base to your
|
||||
GHE URL (e.g. `https://ghe.mycorp.com/api/v3`).
|
||||
|
||||
### 3.1 Automations — GitHub Actions
|
||||
|
||||
Two workflows ship in [`examples/github-actions/`](examples/github-actions). Copy them into
|
||||
your repo and add an `ANTHROPIC_API_KEY` Actions secret (or swap `MODEL` for a
|
||||
provider you have a key for). The built-in `GITHUB_TOKEN` already covers commit
|
||||
statuses, reviews and comments.
|
||||
|
||||
**PR gate — `neurosploit-pr-gate.yml`**
|
||||
Runs on every pull request, reviews the code, and enforces the gate:
|
||||
```bash
|
||||
neurosploit pr "$REPO" "$PR_NUMBER" --model "$MODEL" --comment --fail-on critical -v
|
||||
```
|
||||
To make it actually block merges: *repo Settings → Branches → Branch protection
|
||||
rule* on your default branch → **Require status checks to pass** → select
|
||||
**`neurosploit-pr-gate`**. Add **Require a pull request review** to also honor the
|
||||
REQUEST_CHANGES review it posts.
|
||||
|
||||
**`@neurosploit` mention bot — `neurosploit-mention.yml`**
|
||||
Comment `@neurosploit` on a PR or issue to trigger a scan. Only users with
|
||||
**write** access can trigger it (a permission check guards the model budget).
|
||||
Everything after the mention is the instruction, in **any language**:
|
||||
|
||||
| Comment | Effect |
|
||||
|---------|--------|
|
||||
| `@neurosploit` | white-box review of this PR (blocks on critical) |
|
||||
| `@neurosploit focus SQLi and IDOR` | same, steered by the focus |
|
||||
| `@neurosploit scan https://staging.app` | black-box test of that URL |
|
||||
| `@neurosploit foco em IDOR, fora de escopo /admin` | steered review (Portuguese) |
|
||||
|
||||
The bot reacts 👀 to acknowledge, then posts results back as a comment.
|
||||
|
||||
---
|
||||
|
||||
## 4. GitLab
|
||||
|
||||
Reference in New Issue
Block a user