Saltar a contenido

Integrate and automate

Ostorlab integrates with 10 CI/CD tools (plus App Center, which Microsoft retired), three ticketing systems, Slack, Vanta and four SAML identity providers. It also offers a GraphQL API, an MCP server and a command line for your own automation.

The MCP server and every CI guide except App Center need an Ostorlab API key. The GraphQL API accepts an API key or a user token. App Center uses an App Center API token instead. See API keys and GraphQL API.

CI/CD

To learn how a CI scan works, see Scan in your CI/CD pipeline. For the command options, see CI scan options.

Tool How you connect Page
GitHub The Ostorlab GitHub Action. An optional GitHub App comments on pull requests. GitHub
GitLab The ostorlab/gitlab-ci image, configured with environment variables. GitLab
Jenkins The Ostorlab plugin, as a freestyle build step or a pipeline step. Jenkins
Azure DevOps The Ostorlab extension from the Azure DevOps Marketplace. Azure DevOps
CircleCI The Ostorlab orb. CircleCI
Bitbucket A script step that installs and runs the CLI. Bitbucket
GoCD A command line task that runs the CLI. GoCD
TeamCity A command line step that runs the CLI in the ostorlab/oxo:latest container. TeamCity
Bitrise A script step that installs and runs the CLI. Bitrise
Harness A run step that installs and runs the CLI. Harness
App Center (retired by Microsoft) A webhook, set up from a configuration you create in Ostorlab. It needs no pipeline script. App Center

Microsoft retired Visual Studio App Center on 31 March 2025. See the Microsoft retirement notice. The App Center guide stays for existing configurations.

Source code providers

Tool Use it to Page
GitHub, GitLab, Bitbucket, Azure DevOps, Self-Hosted Git Connect your source code provider so that your repositories are available when you create a source code scan. Source Code Scanning

Ticketing

The Jira and Linear pages state that the organisation must have an enterprise subscription.

Tool Use it to Page
Jira Manage vulnerabilities with Ostorlab tickets and sync them with Jira, one way or two ways. Jira
Linear Manage vulnerabilities with Ostorlab tickets and sync them with Linear, one way or two ways. Linear
ServiceNow Configure authentication and ticket synchronization between Ostorlab and ServiceNow. ServiceNow

Chat and compliance

Tool Use it to Page
Slack Send Ostorlab notifications to your Slack workspace. Slack
Vanta Push vulnerability findings from Ostorlab to Vanta's vulnerability tracking system. Vanta

Single sign-on

Tool Use it to Page
SAML 2.0 Enable centralized single sign-on, so members of your organisation sign in with their work email. Single sign-on (SAML)
Azure Active Directory Configure Azure Active Directory as a SAML SSO identity provider for Ostorlab. SAML with Azure Active Directory
Google Workspace Configure Google Workspace as a SAML SSO identity provider for Ostorlab. SAML with Google Workspace
Okta Configure Okta as a SAML SSO identity provider for Ostorlab. SAML with Okta
OneLogin Configure OneLogin as a SAML SSO identity provider for Ostorlab. SAML with OneLogin

API and MCP

Tool Use it to Page
GraphQL API Create scans, follow their progress and list vulnerabilities from scripts or the GraphiQL sandbox. GraphQL API
MCP server Let AI assistants and agent frameworks work with your scans, vulnerabilities, tickets and assets directly. MCP server
API keys Create and manage the keys that the API, the MCP server and every CI guide except App Center use to authenticate. API keys

Command line

Tool Use it to Page
Ostorlab CLI (oxo) Run ci-scan from any shell step, or drive a scan with a custom list of checks. Scan in your CI/CD pipeline, Custom scans

Choose by situation

I want to Open
Fail a build when the scan risk rating is above a threshold The guide for your CI tool, such as GitHub or GitLab, and CI scan options
Open tickets in Jira or Linear Jira or Linear
Get scan comments on a pull request GitHub, section on the Ostorlab Security Scanner GitHub App
Send notifications to a Slack channel Slack
Let members sign in with their work email Single sign-on (SAML)
Create scans from a script GraphQL API
Ask an AI assistant about my scans MCP server