What it is
The SafeWeave command line runs the scanners on your own computer. Your code never leaves your machine.
Who gets it
Everyone. Without an account you get a few free scans with the basic scanners. With your license key, you get every scanner your plan includes, with no limit on scans.
How to use it
You need Node.js 20 or later.
- Open a terminal in your project folder.
- Set your license key (from the Welcome to SafeWeave page or your email):
export SAFEWEAVE_LICENSE_KEY=your-license-key
- Scan the current directory:
npx -y safeweave-mcp scan .
Options
| Flag | What it does |
|---|---|
--format json|sarif|text |
Output format (default: json). SARIF uploads to GitHub code scanning. |
--fail-on critical|high|medium |
Exit 1 when a finding at this severity or worse exists (default: high). |
--no-fail |
Always exit 0 after a successful scan. |
--allow-partial |
Don't fail when a required scanner could not run. |
--scanners sast,secrets,deps |
Run a subset (still limited to your plan). |
--no-report |
Don't sync finding counts to your dashboard. |
In CI
Add .github/workflows/security.yml to your repository, and store your key as a repository secret named SAFEWEAVE_LICENSE_KEY:
name: SafeWeave
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with: { node-version: 20 }
- run: npx -y safeweave-mcp scan . --format sarif --fail-on high > safeweave.sarif
env:
SAFEWEAVE_LICENSE_KEY: ${{ secrets.SAFEWEAVE_LICENSE_KEY }}
The same command works in GitLab CI, Jenkins and any system with Node.js. On GitHub you can also use the GitHub Action.
What you'll see
A list of findings with severity, file and line, and a security score. The exit code tells CI whether to fail the build.
Limits
- Scanning from the terminal sends only severity counts to your dashboard, never findings, file paths or repository names. Add
--no-reportto send nothing. - Vibe-coded app checks run in SafeWeave's cloud scans of your connected repositories, not in the terminal.
If something goes wrong
- "Unauthorized" or fewer scanners than expected: check that
SAFEWEAVE_LICENSE_KEYis set in the same terminal, and that the key is your current one. If you regenerated it or upgraded your plan, use the new key from your email. npxnot found: install Node.js from nodejs.org.- A scanner could not run: the output says which one. Add
--allow-partialto keep the build green while you look into it.