English | 简体中文
Detect Deep. Gate Early. Secure Code, Secrets & Supply Chain.
Application Security & Governance — the Secure product in AngusKit.
This repository hosts documentation only. AngusSecurity source code is distributed through private deployment packages, not through this GitHub repository. Earlier revisions of this repository contained application source; as of this update, distribution has moved to AngusKit's packaging pipeline (see Get the Community Edition below). This repository now focuses on product information, quickstart guides, and links to the full documentation site.
AngusSecurity runs one check across code flaws, leaked secrets, and dependency/image vulnerabilities, then gates merges and releases by severity — turning scan output into an executable release decision instead of a report nobody reads. It wraps OpenGrep (SAST), Gitleaks (secrets), Trivy (SCA/image), and a SonarQube Scanner integration behind one console, CLI, and API.
- Multi-signal detection out of the box — code security, secrets, and dependency/image vulnerabilities in one job, one result list
- Unified issue governance — normalized, deduplicated findings across engines; timed suppressions for false positives; secrets masked by default
- Merge & release gates — block high-severity findings before merge, complete supply-chain evidence before release
- Alerts & report loop — actionable alerts and archivable reports (JSON/HTML/CSV) for release and audit packs
- Console · CLI · API — pipelines and human review share the same result model, with offline engine bundles for air-gapped use
- Git & artifact linkage — trigger scans on push/PR, gate artifacts at ingest, one integration across the suite
About 280 MB. This zip is AngusGM + AngusSecurity. At least 2 cores / 4 GB RAM and 40 GB disk; reserve another 20 GB for engines and vulnerability data. Docker Engine + Compose v2.
This first-run path matches the official docs: Docker Compose, the install wizard, access mode 2 (bundled Caddy), HTTP :80 (no certificate).
- Resolve names to this machine (or add to
/etc/hostsfor a local trial). Public DNS name in the wizard is the suffix (e.g.example.com), notgm.example.com.
127.0.0.1 gm.example.com security.example.comOpen host 80. App ports stay behind the proxy — do not use localhost:8801. A missing engine can be WARN while doctor: OK — that is not an install failure. Stop Nginx/Caddy/IIS if they already bind 80. On macOS + Docker Desktop, do not run ./install.sh with sudo.
- Download, unzip, and run the wizard from the package root:
curl --fail --location --progress-bar -o AngusSecurity-Community-1.0.0.zip \
https://repo.anguskit.com/raw/raw-public/AngusKit/security/AngusSecurity-Community-1.0.0.zip
unzip AngusSecurity-Community-1.0.0.zip
cd AngusSecurity-1.0.0
./install.shAnswer: Install mode 1 (Compose) → Access 2 (bundled reverse proxy — do not press Enter) → Proxy 1 (Caddy) → TLS 4 (HTTP :80, no certificate) → Database 1 (MySQL 8 in Compose) → Public DNS name = example.com → set admin password (default user admin). Wait for Install finished.
- Confirm health, then open the console:
./bin/angusctl.sh doctorLook for doctor: OK. Open http://gm.example.com/, sign in, then open http://security.example.com/.
Need the full suite? Use AngusKit-Community-1.0.0.zip from AngusKit.
First-run guide: security quickstart · Full install (host ZIP, Helm preview, TLS, offline): install docs
| Community | Team / Enterprise | SaaS | |
|---|---|---|---|
| Price | Free | Paid, private deployment | Paid, hosted |
| Users | Up to 10 | Higher / unlimited seats | Per plan |
| Scan sources (repos/targets) | Up to 20 | Higher / unlimited | Per plan |
| Scans | Up to 100 / month | Higher / unlimited | Per plan |
| SCA, image deep scan, policy gates, Git/artifact integration, MCP | Not included (code defect + secret detection only) | Included | Per plan |
Community Edition source is licensed under GPL-3.0 and distributed with each Community installation package. Team and Enterprise editions are proprietary, governed by the XCan Business License, Version 1.0 (XCBL-1.0), distributed only under a paid subscription.
Full pricing and feature comparison: anguskit.com/pricing
| Product | Focus | Repository |
|---|---|---|
| AngusKit | The full suite (this product + 5 others + AngusGM) | AngusKit/AngusKit |
| AngusAI | AI agent development | AngusKit/AngusAI |
| AngusGit | AI-native code collaboration | AngusKit/AngusGit |
| AngusRepo | Universal artifact management | AngusKit/AngusRepo |
| AngusTester | AI-native software testing | AngusKit/AngusTester |
| AngusInsight | Private product analytics | AngusKit/AngusInsight |
- Full docs: anguskit.com/docs/security
- Contact / sales: anguskit.com/contact ·
sales@anguskit.com - This repository's Issues are for documentation feedback and install troubleshooting. This repository does not accept source code pull requests — see CONTRIBUTING.md.
- This repository's documentation content: see LICENSE (GPL-3.0, matching the Community Edition source it describes).
- AngusSecurity Community Edition product source: GPL-3.0, distributed with each Community installation package.
- AngusSecurity Team / Enterprise Edition: proprietary, XCan Business License, Version 1.0 (XCBL-1.0) — see https://www.anguskit.com/licenses/XCBL-1.0. Distributed under a paid subscription only.

