MAESTRO

CI/CD Integration

Automatically scan your code for threats with every commit using MAESTRO's 7-layer threat model

How It Works
Integrate MAESTRO threat scanning into your CI/CD pipeline in 3 steps
1

Generate API Key

Create an API key from your API Access page

2

Add to CI/CD

Copy the workflow configuration for your platform

3

Deploy Safely

Pipeline blocks if critical threats are detected

Choose Your CI/CD Platform
Select your platform and copy the configuration file

GitHub Actions

File: .github/workflows/maestro-scan.yml

name: MAESTRO Security Scan

on:
  push:
    branches: [ main, develop ]
  pull_request:
    branches: [ main ]

jobs:
  maestro-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      
      - name: MAESTRO Threat Analysis
        run: |
          RESPONSE=$(curl -X POST "https://your-app.base44.app/api/functions/cicdScan" \
            -H "Content-Type: application/json" \
            -H "X-MAESTRO-API-KEY: ${{ secrets.MAESTRO_API_KEY }}" \
            -d '{
              "repository_name": "${{ github.repository }}",
              "repository_url": "${{ github.server_url }}/${{ github.repository }}",
              "branch": "${{ github.ref_name }}",
              "commit_sha": "${{ github.sha }}"
            }')
          
          echo "$RESPONSE" | jq .
          
          CRITICAL_THREATS=$(echo "$RESPONSE" | jq -r '.critical_threats')
          SHOULD_BLOCK=$(echo "$RESPONSE" | jq -r '.should_block_deployment')
          
          echo "Critical Threats: $CRITICAL_THREATS"
          
          if [ "$SHOULD_BLOCK" == "true" ]; then
            echo "❌ Deployment blocked due to critical threats"
            exit 1
          else
            echo "✅ No critical threats found"
          fi

⚠️ Important Setup Steps:

  1. Replace your-app.base44.app with your actual MAESTRO app URL
  2. Add your API key as a secret named MAESTRO_API_KEY in your CI/CD platform
  3. The scan will automatically block deployment if critical threats are found
API Response Format
{
  "status": "success",
  "system_id": "abc123",
  "total_threats": 12,
  "critical_threats": 2,
  "high_threats": 5,
  "should_block_deployment": true,
  "summary": "Found 12 threats (2 critical, 5 high)",
  "dashboard_url": "https://your-app.base44.app/SystemDetails?id=abc123",
  "threats": [
    {
      "threat_title": "Unauthorized Access to Foundation Model",
      "severity_level": "critical",
      "maestro_layer": "foundation_models",
      ...
    }
  ]
}