Aspen: Guardian AI
Aspen Guardian turns reactive scanner findings into proactive guidance for your AI.
Overview
How It Works
-
It transforms these findings into rules your AI assistant can use to prevent and remediate future vulnerabilities.
-
It updates your rules file through a pull request, allowing you to review, modify, and approve the changes.
The Result
Supported Scanners
Guardian Action currently supports the following security scanners:
- Bandit - Python security scanner
- Snyk - Multi-language dependency and code scanner
Support for additional scanners is planned for future releases.
To integrate with Guardian, scanners must produce JSON-formatted output that the Guardian service can ingest and process.
If you have a scanner you’d like to use that isn’t currently supported, please reach out to your Account Manager or contact us at support@securityjourney.com.
Configuration and Setup
Prerequisites
To complete this setup in GitHub, you must have the following access:
-
Organization or Repository Admin access
Required to add or manage secrets (e.g., Actions secrets, environment secrets). -
Write/Commit access to the repository
Required to create or update GitHub Actions workflows (files in.github/workflows/). -
Note: CODEOWNERS restrictions may apply
If the repository uses aCODEOWNERSfile, workflow changes may require review and approval from designated code owners before they can be merged.
Complete Setup Instructions
For step-by-step setup instructions and configuration details, refer to our published Aspen: Guardian AI documentation.
Need Help Integrating with CI/CD?
Want to integrate Aspen: Guardian AI into your CI/CD pipeline? Contact your Account Manager or email support@securityjourney.com