Integrations

Inside the tools you already use.

No dashboard to adopt, no service to connect, no agent on your servers. Bracel runs in GitHub Actions, reports on the pull request, and works with a defined Node.js toolchain.

Required or built in Validated end to end Supported or recommended

01

GitHub

Where the check runs and where its verdict lands.

  • Required

    GitHub Actions

    Where every check runs

    The pull_request trigger on GitHub-hosted ubuntu-24.04 runners, in your own account. The action is pinned by full commit SHA.

  • Required

    Pull requests

    Where the verdict appears

    The check summary lands on the pull request: approved rule, why it ran, expected, observed, why, next step and provenance.

  • Supported

    Workflow artifacts

    Optional evidence file

    An opt-in JSON evidence file with the same fields as the summary, kept 7 days in your repository.

  • Recommended

    Code owners

    Protects the rules

    Protect .github/workflows/ and the rules file with CODEOWNERS, so changes to Bracel itself always get review.

  • Supported

    Branch protection

    Optional merge gate

    Bracel changes no merge settings. Your administrators decide whether the check is required.

02

Runtime and frameworks

The application profile validated end to end.

  • Required

    Node.js 24

    Application runtime

    Your application runs on Node.js 24 inside the release’s isolated environment. engines.node, if set, must allow 24.

  • Validated

    Express 4

    Web framework

    Validated end to end with JavaScript (ES modules) and with TypeScript 5.

  • Validated

    NestJS 11

    Web framework

    Validated end to end with TypeScript 5 on @nestjs/platform-express.

  • Validated

    TypeScript 5

    Language

    Compiled by an npm build script that runs tsc without network access.

03

Packages and isolation

How the application is installed and contained.

  • Required

    npm

    Package manager

    package-lock.json version 2 or 3, packages from the public npm registry with sha512 integrity, no workspaces.

  • Built in

    Docker

    Isolation

    The runtime image is pinned by digest. Your application runs without network access, writing only to /tmp.

Not supported yet

Outside the profile, you get an answer. Never a silent pass.

Each of these produces an explicit UNKNOWN with the reason and what to change. We list them so you can decide before you try.

Check your repository
  • GitLab, Bitbucket and other CI systems
  • Self-hosted runners
  • Yarn, pnpm and Bun
  • Monorepos and workspaces
  • Private registries, git dependencies and tarball URLs
  • Applications that need a database or other service to start
  • Languages other than JavaScript and TypeScript

Product names and logos are trademarks of their owners. They are shown only to say that Bracel works with these products, not to imply endorsement or partnership.