Hamburger Cross Icon

Integration Library

30+ Integrations for Your Stack

Connect Lunar to your engineering tools. Collectors and catalogers automatically gather data from your codebase, CI/CD pipelines, and external systems.

One-time setup, continuous data. Each integration runs automatically, feeding rich metadata to guardrails that enforce your standards in PRs and AI workflows.

50+ more integrations coming soon — expanding coverage across language ecosystems, service catalogs, cloud, CI/CD, and security tools.

Browse Integrations

45 integrations
.NET Collector

.NET Collector

Collector

Analyze .NET projects to collect project structure, target frameworks, NuGet dependencies, and test project identification. Supports C#, F#, and VB.NET with SDK-style and legacy projects.

AI Collector

AI Collector

Collector

Track tool-agnostic AI coding assistant usage across your organization. Collects agent instruction files, plans directories, and AI authorship annotations. Part of the unified ai.* namespace.

AST-Grep Collector

AST-Grep Collector

Collector

Analyze source code using AST-based pattern matching with ast-grep. Define custom rules to detect security issues, anti-patterns, and code style violations.

Backstage Collector

Backstage Collector

Collector

Parses and lints Backstage catalog-info.yaml files. Writes the raw Backstage descriptor (apiVersion, kind, metadata, spec) to .catalog.native.backstage, preserving annotations as-is.

C/C++ Collector

C/C++ Collector

Collector

Analyze C/C++ projects to collect build system info (CMake, Make, Meson, Autotools), dependency graphs, cppcheck linting, and CI compiler commands. Enforce C/C++ engineering standards.

Checkov Collector

Checkov Collector

Collector

Auto-runs Checkov on infrastructure code (Terraform, CloudFormation, Kubernetes, Dockerfiles) and detects Checkov CI executions. Results are normalized into .iac_scan for the iac-scan policy.

CI OpenTelemetry Collector

CI OpenTelemetry Collector

Collector

Instruments CI pipelines with OpenTelemetry distributed tracing. Captures job, step, and command-level spans for detailed CI observability. Sends traces to any OTLP-compatible backend (Tempo, Jaeger, etc.).

Claude Collector

Claude Collector

Collector

Detects Claude Code Review on pull requests, captures Claude CLI invocations in CI, discovers CLAUDE.md instruction files, and runs custom Claude prompts against code. Writes to normalized ai.code_reviewers[] plus Claude-specific data in ai.native.claude.

Codecov Collector

Codecov Collector

Collector

Automatically detect Codecov runs in CI and fetch coverage percentage and file-level details. Track test coverage trends across your organization.

CodeQL Collector

CodeQL Collector

Collector

Detects GitHub CodeQL security scanning via GitHub Code Scanning check-runs or CLI integration in CI pipelines. Writes to normalized SAST Component JSON paths, enabling tool-agnostic SAST policies.

CodeRabbit Collector

CodeRabbit Collector

Collector

Detects CodeRabbit AI code review activity on pull requests by querying GitHub check-runs API, and collects CodeRabbit configuration files. Writes to normalized ai.code_reviewers[] for tool-agnostic policy checks, plus tool-specific data in ai.native.coderabbit.

Codex Collector

Codex Collector

Collector

Detects OpenAI Codex CLI invocations in CI pipelines. Records command strings, versions, and flags for policy-level analysis. Writes to ai.native.codex under the unified ai.* namespace.

Dependabot Collector

Dependabot Collector

Collector

Parses .github/dependabot.yml to collect dependency update configuration including covered ecosystems, update schedules, and directory targets. Enables enforcement of dependency automation standards.

Docker Collector

Docker Collector

Collector

Parse Dockerfiles to extract base images, labels, and security configuration. Capture Docker build commands in CI for traceability and compliance enforcement.

DR Documentation Collector

DR Documentation Collector

Collector

Parse disaster recovery plan and exercise documentation to extract RTO/RPO targets, exercise dates, review timestamps, and section headings. Verify that teams document and regularly practice recovery procedures.

Gemini Collector

Gemini Collector

Collector

Detects Google Gemini CLI invocations in CI pipelines. Records command strings, versions, and flags for policy-level analysis. Writes to ai.native.gemini under the unified ai.* namespace.

GitHub Actions Collector

GitHub Actions Collector

Collector

Parses and lints GitHub Actions workflow files. Extracts structured data from every workflow (triggers, jobs, action references), runs actionlint for syntax and type checking, and classifies version pinning status for all third-party action references.

GitHub Collector

GitHub Collector

Collector

Automatically collect GitHub repository settings, branch protection rules, and access permissions. Enforce VCS standards across your organization.

GitHub Org Cataloger

GitHub Org Cataloger

Cataloger

Sync repositories from GitHub organizations into your Lunar catalog. Automatically track visibility, topics, and metadata across all repos with configurable filtering.

Gitleaks Collector

Gitleaks Collector

Collector

Detects hardcoded secrets using Gitleaks in two modes: auto-runs scans on every repo, and detects existing Gitleaks executions in CI pipelines to collect their report files. Results are written to the normalized .secrets Component JSON category.

Go Collector

Go Collector

Collector

Analyze Go projects to collect module info, dependencies, test coverage, and golangci-lint results. Enforce Go-specific engineering standards.

Grafana Collector

Grafana Collector

Collector

Query the Grafana API for dashboards and alerts linked to each component, and scan the component repo for Grafana dashboard JSON files. Normalizes to .observability for tool-agnostic policies; raw data at .observability.native.grafana.

Helm Collector

Helm Collector

Collector

Parse Helm charts to extract chart metadata, lint validation results, values schema presence, and dependency version constraints. Runs helm lint on discovered charts and normalizes results for policy evaluation.

HTML Collector

HTML Collector

Collector

Detect HTML, CSS, SCSS, and LESS files, run HTMLHint and Stylelint for code quality analysis. Categorize frontend markup projects and surface lint issues for policy enforcement.

Java Collector

Java Collector

Collector

Analyze Java projects to collect build tool info, dependencies, CI/CD command tracking, test scope, and JaCoCo coverage. Supports Maven and Gradle.

Jira Collector

Jira Collector

Collector

Extract Jira ticket references from pull request titles, validate them against the Jira REST API, and detect ticket reuse across PRs.

Kubernetes Collector

Kubernetes Collector

Collector

Parse Kubernetes YAML manifests to extract workloads, containers, resource limits, probes, PodDisruptionBudgets, and HorizontalPodAutoscalers. Capture kubectl commands in CI for deployment traceability.

License Origins Collector

License Origins Collector

Collector

Scan dependency license files for geographic origin signals — country names in copyright lines, governing law clauses, and author addresses. Results are cached in Postgres for fast repeat scans across projects.

Linear Collector

Linear Collector

Collector

Extract Linear ticket references from pull request titles, validate them against the Linear GraphQL API, and detect ticket reuse across PRs.

Manifest Cyber Collector

Manifest Cyber Collector

Collector

Integrates with Manifest Cyber's SBOM management platform to collect vulnerability enrichment, license compliance, and SBOM lifecycle data. Supports API and CI CLI integration methods.

Node.js Collector

Node.js Collector

Collector

Analyze Node.js projects to collect package metadata, dependencies, test coverage, and CI/CD command tracking. Enforce Node.js-specific engineering standards.

OpenAPI Collector

OpenAPI Collector

Collector

Detect OpenAPI and Swagger spec files in repositories (any version — Swagger 1.x/2.0, OpenAPI 3.0/3.1+). Writes spec metadata to `.api.spec_files[]` and full raw specs to `.api.native.openapi`. Handles both naming conventions in YAML and JSON formats.

PagerDuty Collector

PagerDuty Collector

Collector

Query the PagerDuty API to collect on-call schedule, escalation policy, and current responder data. Normalizes results into the .oncall category for tool-agnostic policy evaluation.

PHP Collector

PHP Collector

Collector

Analyze PHP projects to collect Composer metadata, dependencies, tool configuration (PHPUnit, PHPStan, Psalm, PHP-CS-Fixer, PHPCS), and CI/CD command tracking. Enforce PHP-specific engineering standards.

Python Collector

Python Collector

Collector

Analyze Python projects to collect build tool info, dependencies, test coverage, and CI/CD command tracking. Enforce Python-specific engineering standards.

Renovate Collector

Renovate Collector

Collector

Parses Renovate config (renovate.json, .renovaterc, .renovaterc.json, or the renovate key in package.json). Slurps the full parsed config to .dep_automation.native.renovate and exposes normalized fields (extends, enabled managers) at .dep_automation.renovate for policy use.

Repo Boilerplate Collector

Repo Boilerplate Collector

Collector

Aggregates repository boilerplate metadata by scanning for README files, CODEOWNERS ownership rules, and common configuration files (.gitignore, LICENSE, SECURITY.md, CONTRIBUTING.md, .editorconfig). Consolidates readme and codeowners collectors into a single plugin.

Ruby Collector

Ruby Collector

Collector

Analyze Ruby projects to collect Bundler metadata, dependencies, Ruby version, and CI/CD command tracking. Detects Gemfile, .ruby-version, Rakefile, and gemspec files.

Rust Collector

Rust Collector

Collector

Analyze Rust projects to collect crate metadata, dependencies, unsafe block usage, test coverage, and clippy lint results. Supports Cargo workspaces.

Semgrep Collector

Semgrep Collector

Collector

Detects Semgrep security scanning via GitHub App or CLI integration. Automatically categorizes results (SAST for code analysis, SCA for Supply Chain) and writes to normalized Component JSON paths.

Shell Collector

Shell Collector

Collector

Detect shell scripts (.sh, .bash) in a repository and run ShellCheck for automated static analysis. Writes language detection data and lint results to Component JSON. Skips gracefully if no shell scripts are found.

Snyk Collector

Snyk Collector

Collector

Detects Snyk security scanning via GitHub App or CLI integration. Automatically categorizes results (SCA, SAST, Container, IaC) based on scan type and writes to normalized Component JSON paths.

Syft SBOM Collector

Syft SBOM Collector

Collector

Generate Software Bill of Materials automatically or detect existing Syft SBOM generation in CI pipelines. Supports CycloneDX and SPDX formats with license detection for Go, Java, Node.js, Python, and Rust.

Terraform Collector

Terraform Collector

Collector

Parse Terraform HCL files to extract configuration data. Writes file validity and full parsed HCL JSON for downstream policy analysis of providers, modules, backends, resources, and infrastructure security posture.

Trivy Vulnerability Scanner Collector

Trivy Vulnerability Scanner Collector

Collector

Automatically scans repository dependencies for known CVEs using Trivy. Supports Go, Node.js, Python, Java, Rust, and many other ecosystems. Writes normalized vulnerability data to .sca for use with the SCA policy. No secrets or vendor accounts required.

How Integrations Power Guardrails

Step 1

Integrations Gather Data

Collectors and catalogers automatically extract metadata from your codebase, CI/CD pipelines, and external systems

Step 2

Guardrails Enforce Standards

Guardrails evaluate the collected data and provide real-time feedback in PRs and AI workflows

Need a Custom Integration?

Build your own collectors and catalogers with simple Bash scripts. Connect any tool or API to Lunar's guardrail ecosystem.

Ready to Automate Your Standards?

See how Lunar can turn your AGENTS.md, engineering wiki, compliance docs, or postmortem action items into automated guardrails with our 100+ built-in guardrails.

Works with any process
check AI agent rules & prompt files
check Post-mortem action items
check Security & compliance policies
check Testing & quality requirements
Automate Now
Paste your AGENTS.md or manual process doc and get guardrails in minutes
Book a Demo