Skip to content

Developer portal

CI/CD — GitHub Action

Shift-left by scanning targets on every pipeline run. Compare against a baseline scan to fail on regressions.

GA

Scan on every run

- uses: qtangl/qtangl/.github/actions/qtangl-scan@main
  with:
    api-key: ${{ secrets.QTANGL_API_KEY }}
    target: api.example.com
    api-url: https://api.qtangl.com

Verify signed reports in CI

After a scan exports a signed JSON report, verify integrity with the published qtangl-verify package or the composite action.

- uses: qtangl/qtangl/.github/actions/verify@main
  with:
    report-path: artifacts/report.json
    api-base: https://api.qtangl.com

# Or install directly:
# pip install qtangl-verify
# qtangl-verify artifacts/report.json --api-base https://api.qtangl.com --json

Fail on regression

Set baseline-scan-id to a golden scan. The action compares new quantum-vulnerable findings and exits non-zero when regressions are detected (v2 action).

Monitor setup · Verify specification · Coverage matrix