GitHub Action
Run a pentest in your pipeline, gate the build on exploited findings, and attach the report to the run.
One autonomous pentest engine, reachable from your IDE, your pipeline, your automation platform and your SOC. Each surface auto-detects its edition: the community CLI reads your local JSON report, and the paid Pro tier adds the live REST API, streaming and remediation.
The same open-source engine, wired into your IDE, your CI/CD, your automation and your SecOps stack. Each surface auto-detects its edition: the community CLI runs on your local JSON report; the paid Pro tier adds the live REST API, streaming and remediation.
IDE, CI/CD, automation, observability and the SDK underneath them all. Pick the category that matches how your team already works.
Gate the build on exploited findings and attach the report to the run.
Browse findings and launch a campaign without leaving the editor.
Orchestrate campaigns and read findings from a low-code workflow.
Ship safe-field posture data into the dashboards your SOC already watches.
The shared client every surface is built on.
Every link below is verified. Where a marketplace listing is still in review, we point you at the repository releases instead of a page that would 404.
Run a pentest in your pipeline, gate the build on exploited findings, and attach the report to the run.
A catalogue component that runs the scan and emits GitLab Code-Quality and SAST reports.
A pipeline step (darkmoonScan) that publishes SARIF into Warnings-NG. Update Center listing pending.
Browse findings and launch a campaign from the editor; Pro adds live status and the dashboard.
Same browse/launch flow across the IntelliJ family; Pro adds streaming and remediation review.
Trigger campaigns and read Finding / Retest / Metric / Webhook operations from a workflow. Consumes the Pro REST API.
Security-posture dashboards over the Pro REST API. grafana.com catalog submission pending.
OSS exports safe-field JSON to HEC; Pro adds REST pull and a 'Send to Darkmoon' alert action. Splunkbase approval pending.
The shared client every integration builds on: an oss-local backend (local JSON + darkmoon.sh) and a pro-http backend (full /api/v1).
Every "OSS + Pro" surface degrades to the local engine: it reads the JSON report your darkmoon.sh / darkmoon-ci run writes to a bind-mounted data dir, and can browse, launch and gate a build without any network. No dashboard, no streaming, no remediation.
The paid tier adds live SSE streaming, the hosted dashboard, remediation→PR (always UI-gated, never auto-merged), the scheduler and HMAC-signed webhooks. The n8n node and the shipped Grafana datasource are REST consumers, so they are Pro only.
Across every integration, only safe metadata leaves the host, severity, status, ids, MITRE tags and timestamps. Evidence bodies, secrets and raw requests/responses never cross the API, the webhooks or the event stream.
Automation-first, CI-first, IDE-first or SOC-first, the same open-source engine underneath, with an optional Pro control plane.