Skip to content

Continuous Security Testing

Use Escape to start scans from your CI/CD workflows. A profile's CI/CD page shows its ID and your API key for your CI variables, with links to platform-specific examples.

Supported Integrations

Escape supports multiple CI/CD platforms:

Additional integration options:

Upvote your integrations

We're actively developing additional integrations. Share your requirements to help us prioritize development.

Automatic Scan Triggers

Escape offers two types of scan triggers in your CI/CD pipelines:

  1. Non-blocking scan: Starts the scan and returns without waiting (default behavior)
  2. Blocking scan: Waits for a terminal scan state (enabled by --watch). Use a quality-gate script to require a FINISHED scan and check open issues. The script sets the build result; --watch waits for completion and can return success for failed or canceled scans and scans with findings.

Platform Integration Features

  • Full security scan capabilities
  • Dynamic configuration overrides
  • Schema validation and updates
  • Detailed security reporting

Compatibility with the Escape Security Platform

All CI/CD integrations include:

  • Application configuration from Escape platform
  • Team notifications through configured channels
  • Integration with Workflows

Scan Configuration Overrides

Configure scans dynamically at runtime:

  • Update authentication headers
  • Modify scan parameters
  • Set environment-specific configurations

Schema Upload

Maintain schema synchronization:

  • Programmatic schema updates
  • Automatic endpoint synchronization
  • Version control integration

Example Usage

Integrate Escape into your Gitflow workflow:

  • Automated scans on branch commits
  • Pre-deployment security validation