Back to docs

Installation Methods

GitHub App

The BLAZLE GitHub App scans every Pull Request for secrets, leaked credentials, and destructive commands, acting as the final security gate before code reaches your main branch. It is the same app that guards every repository at BLAZLE and Kolerr Lab.

Installation

Navigate to the Integrations tab in your BLAZLE dashboard and click Connect GitHub. Authorize the BLAZLE GitHub App on your organization or selected repositories.

How it works

When a Pull Request is opened or updated, GitHub sends a webhook to BLAZLE. BLAZLE fetches the PR diff and scans it instantly using the BLAZIL Engine, in milliseconds.

Scan results are logged to your Dashboard under Intercepts with full finding details, regardless of which blocking mode is active.

Blocking Modes

BLAZLE offers two levels of enforcement, both toggled from the Intercepts page in your Dashboard.

In-flight ONSoft Block (Default)

When a violation is detected, BLAZLE posts a REQUEST_CHANGES review comment on the Pull Request warning the author to remove the secret and amend their commit. The Merge button remains available; this mode is advisory only.

Hard Block ONHard Block (Opt-in)

When enabled, BLAZLE also posts a GitHub Commit Status (context: "BLAZLE Security Scan") to the head commit of every PR: failure if threats are detected, success if the PR is clean.

⚠️ One additional step required on GitHub: GitHub only enforces a commit status if your repository has a Branch Protection Rule requiring it. Without this rule, the status is visible but does not block merging.

Test fixtures and example values

Every finding shows the file and line where it was added. BLAZLE judges the value itself, not where it sits: a real-looking key blocks the merge in any file, including tests and docs. Well-known example values (such as keys containing EXAMPLE or long runs like AAAAAA) are listed as Review and do not block.

For test fixtures, use an obviously fake value or build it at runtime. For a generic finding (not a known key format), you can add blazle:allow in a comment on the same line or the line above. It lowers that finding to Review, never applies to known key formats, is written to your audit log, and can be turned off for your workspace.

Enabling Hard Block: GitHub Setup

To make the Hard Block physically prevent merging, configure your GitHub repository:

  1. Go to your GitHub repository → Settings → Branches.
  2. Click Add branch protection rule and set the branch name to main (or your default branch).
  3. Enable "Require status checks to pass before merging".
  4. In the search box, type and select BLAZLE Security Scan.
  5. Save the rule.

Once configured, GitHub will grey out the Merge button on any PR where BLAZLE has posted a failure status, until the developer removes the violation and re-pushes.

Why can't BLAZLE block direct pushes to main?

GitHub webhooks are passive observers: they fire after a push has already landed. BLAZLE has no mechanism to reject a push mid-flight. The correct way to prevent direct pushes to protected branches is to enable the "Restrict who can push to matching branches" option inside your Branch Protection Rule on GitHub. This is a GitHub-side setting and does not require any additional BLAZLE configuration.