Skip to content
NoHack PREvery pull request · GitHub

A security review on every pull request.

Install the GitHub App. On every push, NoHack audits the exact head commit for code flaws, vulnerable dependencies, and leaked secrets, and reports only what touches the lines that changed.

audits per push: code, dependencies, secrets
3
audits per push: code, dependencies, secrets
comment per pull request, kept current
1
comment per pull request, kept current
minute ceiling, so reviews never wait long
20
minute ceiling, so reviews never wait long
capped audits reported as clean
0
capped audits reported as clean
01

From push to review comment.

Scoped to the change, so the comment stays short.

  1. 01 · push

    A commit lands

    The GitHub App picks up the push on any pull request, including from forks. A newer push cancels the audit of the older one.

  2. 02 · audit

    Audit the head commit

    Code, dependency, and secret audits run in parallel on the exact commit. The code audit walks the call graph backwards from what changed.

  3. 03 · scope

    Scope to the diff

    Only findings on changed lines are reported. Deleted code is checked too, because removing a check can be a regression.

  4. 04 · report

    Comment and annotate

    One comment with a severity summary and a table of findings, updated in place. Line annotations land on the diff.

  5. 05 · gate

    Gate the merge

    The check fails on critical, high, or a verified secret; it is neutral on low and medium; it passes when clean.

  6. 06 · continuous

    Keep the baseline current

    With continuous mode on, pushes to the repository trigger delta audits, so the full picture stays current between full audits.

02

Review that respects the reviewer.

Changed lines only

Existing debt doesn’t bury the change under review. What the PR introduced is what the PR is told about.

One comment, kept current

Each push edits the same comment instead of adding another. The thread stays readable.

A check you can require

Make the NoHack check required in branch protection to block merges on critical findings and verified secrets.

Bounded cost

Every PR audit has a time, endpoint, and token ceiling. An audit cut short says so and is never reported as clean.

03

What lands on the pull request.

One comment, one check, and a link to the full finding with its proof.

nohack-labsbotcommented · editedSample · PR #8841

Security Scan Results

3 findings on changed lines of 4f1c2e9 · code, dependencies, secrets

SeverityFindingLocation
CriticalSQL injection in order searchservices/order.ts:131
HighVerified secret: payment API keyconfig/payments.ts:7
Mediumaxios 1.6.0 · CVE-2023-45857package.json:23
NoHack PR · failing: 1 critical, 1 verified secretRequired
  • Summary

    Severity counts for the change, so the reviewer knows in one line whether to stop.

  • Table

    Severity, title, and file:line for each finding, each linking to the full proof in the platform.

  • Check

    Fails on critical, high, or a verified secret. Neutral on low and medium. Passes when clean.

04 · Questions

What teams ask before an audit.

Something else? Email us.

Which Git providers are supported?

GitHub: github.com, GitHub Enterprise Cloud, and GitHub Enterprise Server, through your own GitHub App, set up with a guided flow. Repositories can also be audited from a git URL or a zip upload outside the PR flow.

Does it open fix pull requests?

Not today. Each finding links to its proof and a specific fix inside the platform, where you can ask Aaron to generate a patch.

Will it slow our pipeline?

Audits run asynchronously on the GitHub App’s side with a 20-minute ceiling. Your CI does not wait on it unless you make the check required.

Security at the speed you ship.

Bring a repository, a web app, or an APK. We will walk you through a real audit of it.