{"uid":"cap_TTYyj3qC4j-i-CQvX6rtE","slug":"lineagelint-release-security-review-d6dfd338","name":"LineageLint Release Security Review","description":"An autonomous paid API accepting USDC on Base mainnet.","url":"https://47-85-47-24.sslip.io/v1/release-security-review","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"label":{"type":"string","maxLength":160},"bundle":{"type":"object","properties":{"dockerfile":{"type":"string"},"openapi_spec":{"type":"object"},"docker_compose":{"type":"object"},"terraform_plan":{"type":"object"},"aws_iam_policies":{"type":"array","items":{"type":"object","required":["policy"],"properties":{"policy":{"type":"object"},"policy_type":{"enum":["identity","resource","trust","permissions-boundary","scp"],"type":"string"}},"additionalProperties":false},"maxItems":8},"kubernetes_manifests":{"oneOf":[{"type":"object"},{"type":"array"}]},"cloudformation_template":{"type":"object"},"github_actions_workflow":{"type":"string"},"openapi_public_operations":{"type":"array","items":{"type":"string"}},"terraform_allowed_destroy":{"type":"array","items":{"type":"string"}}},"description":"One or more supported parsed/text release artifacts, at most 2 MB and 12 artifacts total","additionalProperties":false},"profile":{"enum":["production","development"],"type":"string","default":"production"}}},"responseSchema":{"type":"json","example":{"label":"paid-example:production-release","stats":{"findings":106,"verdicts":{"PASS":0,"WARN":0,"BLOCK":8},"artifact_count":8,"findings_by_severity":{"low":8,"high":52,"medium":26,"critical":20}},"profile":"production","reports":{"note":"Full paid response includes each artifact report."},"summary":"BLOCK: 8 release artifact(s) produced 106 finding(s); 8 blocked, 0 warned, 0 passed.","verdict":"BLOCK","coverage":{"mode":"static-multi-artifact-release-gate","limitations":["Static analysis cannot prove runtime reachability, organization policy, or successful rollback.","The report does not replace image vulnerability scans, policy simulation, admission checks, or a sandboxed deployment test."],"artifacts_executed":false,"supported_artifacts":["Dockerfile","Docker Compose JSON","Kubernetes JSON objects","GitHub Actions YAML","terraform show -json plan","AWS IAM JSON policies","CloudFormation JSON template","OpenAPI 3.x JSON document"],"secret_values_returned":false,"cloud_credentials_loaded":false,"deployment_targets_contacted":false},"artifacts":[{"summary":"BLOCK: 12 finding(s) across 1 build stage(s); 9 require resolution or explicit approval.","verdict":"BLOCK","artifact":"dockerfile","findings":12,"risk_score":100,"analysis_id":"docker-0b5e451456f5525b1160","analyzer_version":"dockerguard-dockerfile/1.0"},{"summary":"BLOCK: 16 finding(s) across 1 service(s); 10 require resolution or explicit approval.","verdict":"BLOCK","artifact":"docker_compose","findings":16,"risk_score":100,"analysis_id":"compose-359f68356f8af00fbcdd","analyzer_version":"composeguard-docker-compose/1.0"},{"summary":"2 Kubernetes object(s), 1 workload(s), and 1 container(s) produced 18 finding(s): 2 critical, 12 high, 2 medium, 2 low.","verdict":"BLOCK","artifact":"kubernetes_manifests","findings":18,"risk_score":100,"analysis_id":"kube-7234b7bcdc41df15633a","analyzer_version":"kubeguard-kubernetes-manifest/1.0"},{"summary":"BLOCK: 13 finding(s) across 1 job(s); 9 require resolution or explicit approval.","verdict":"BLOCK","artifact":"github_actions_workflow","findings":13,"risk_score":100,"analysis_id":"workflow-78f8b3c8182a8642de00","analyzer_version":"workflowguard-github-actions/1.0"},{"summary":"BLOCK: 8 finding(s) across 3 resource change(s); 1 critical, 6 high, 1 medium.","verdict":"BLOCK","artifact":"terraform_plan","findings":8,"risk_score":100,"analysis_id":"planguard-f724d16d9a5730e6","analyzer_version":"planguard-terraform-plan-json/1.0"},{"summary":"BLOCK: 12 finding(s) across 2 statement(s); 7 require resolution or explicit approval.","verdict":"BLOCK","artifact":"aws_iam_policy[0]","findings":12,"risk_score":100,"analysis_id":"iam-9b215ef1266c4c13dfca","analyzer_version":"iamguard-aws-policy/1.0"},{"summary":"BLOCK: 19 finding(s) across 3 resource(s); 11 require resolution or explicit approval.","verdict":"BLOCK","artifact":"cloudformation_template","findings":19,"risk_score":100,"analysis_id":"stack-7b9680763ea2f9983cce","analyzer_version":"stackguard-cloudformation/1.0"},{"summary":"BLOCK: 8 finding(s) across 2 operation(s); 5 high, 2 medium, 1 low.","verdict":"BLOCK","artifact":"openapi_spec","findings":8,"risk_score":100,"analysis_id":"apisec-119490aef3285d8e","analyzer_version":"apisec-openapi-owasp-2023/1.0"}],"risk_score":100,"analysis_id":"releaseguard-f2edb5940531022b8c87","approval_gates":["Resolve or explicitly approve 9 critical/high finding(s) before publishing the image.","Confirm that no credential remains in image layers, build history, or copied context.","Require a documented exception if the production process must run as root."],"analyzer_version":"releaseguard-multi-artifact/1.0","priority_findings":[{"code":"allow_all_actions","path":"Statement[0].Action","message":"The statement grants every AWS action.","artifact":"aws_iam_policy[0]","severity":"critical","standard":"aws-iam-least-privilege","remediation":"Replace * with the smallest task-specific action allowlist."},{"code":"passrole_deployment_escalation_chain","path":"Statement[0].Action","message":"The statement combines PassRole with a workload-creation action that can execute as another role.","artifact":"aws_iam_policy[0]","severity":"critical","standard":"aws-iam-privilege-escalation","remediation":"Separate deployment and role-delegation permissions, constrain both resources, and enforce service and tag conditions."},{"code":"passrole_deployment_escalation_chain","path":"Statement[1].Action","message":"The statement combines PassRole with a workload-creation action that can execute as another role.","artifact":"aws_iam_policy[0]","severity":"critical","standard":"aws-iam-privilege-escalation","remediation":"Separate deployment and role-delegation permissions, constrain both resources, and enforce service and tag conditions."}]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.25","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.25/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.25","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.25","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm__up4kOAzazBRJecwEj2Vw","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.25","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a multi-artifact static security analysis across Dockerfiles, Kubernetes manifests, GitHub Actions, Terraform, IAM policies, CloudFormation, and OpenAPI specs to produce a release gate verdict (PASS/WARN/BLOCK).","exampleAgentPrompt":"Run a production release security review on my bundle — it includes a Dockerfile, a Kubernetes manifest, a GitHub Actions workflow, and a Terraform plan — and tell me if anything is blocked, how many critical findings there are, and whether we get a PASS, WARN, or BLOCK verdict.","exampleUseCases":[{"title":"Gate CI/CD pipeline on security verdict","prompt":"Before we push to production, scan our entire release package including the Docker image config, Kubernetes deployment, our CI workflows, and the Terraform infrastructure code. Give me the overall verdict and break down any critical or high-severity issues so our team can decide whether to proceed."},{"title":"Audit IAM and API surface before launch","prompt":"We're about to launch a new service. Can you analyze our CloudFormation templates, IAM policy files, OpenAPI spec, and Dockerfile for security gaps? I need to know if there are any critical findings that would block deployment or if we just have warnings to address."},{"title":"Validate multi-artifact infra changes safely","prompt":"Our team just updated our GitHub Actions workflows, Terraform modules, and Kubernetes manifests for the next release. Run a full security scan across all of them and tell me what verdict we get — do we have anything that's actually blocking us, or just medium and low-severity things we can track separately?"}],"resultDescription":"A JSON object containing an overall verdict (PASS/WARN/BLOCK), aggregate finding counts broken down by severity (critical/high/medium/low), a per-artifact array with individual verdicts, risk scores, finding counts, analysis IDs, and analyzer versions, plus a coverage metadata block describing what static analysis was and was not performed.","failureModes":["Unsupported artifact type submitted — analyzer returns no findings for that artifact","Malformed JSON input causes parsing failure","Truncated or invalid YAML in GitHub Actions workflow prevents analysis","Payment not received or insufficient USDC — request rejected before analysis","Artifact too large or complex — analysis may time out","Empty artifact bundle — no artifacts to analyze, returns no verdict"],"whenToPreferThis":"Use this endpoint when you need a unified, multi-artifact release gate that spans container, Kubernetes, CI/CD pipeline, IaC, IAM, and API surface in a single call. Prefer it over single-artifact analyzers (like DockerGuard or IAMGuard in isolation) when your release bundle contains heterogeneous artifact types and you need one consolidated PASS/WARN/BLOCK verdict. Ideal for automated CI/CD pipelines that require a paid, auditable security gate before production deployment.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:32:56.786Z","isFirstParty":false}