Sorts user guide
Last updated: Sep 30, 2026
This page explains how to configure and use Sorts. Sorts is the Fluid Attacks tool that assesses the vulnerability probability of the files in a code repository.
CLI structure
The Sorts command-line interface (CLI) has this structure:
sorts [OPTIONS] REPOSITORY_PATHWith the options, you analyze repositories or commits and set the output format.
Repo mode
Repo mode analyzes one repository.
It makes a file with the vulnerability probability of each file.
To use Repo mode,
add the --mode flag with the repo argument.
Example:
m gitlab:fluidattacks/universe@trunk /sorts --mode repo path/to/repositoryIn Repo mode, set the output file format with the --out option. The
available formats are JSON (default) and CSV.
CI mode
CI mode integrates Sorts into your CI/CD pipeline.
Use it in the phase where reviewers approve commits before the merge.
Sorts checks the mean risk of a commit.
It then adjusts the necessary approvers with the rules of a configuration file.
To use CI mode,
add the --mode flag with the ci argument.
Example:
m gitlab:fluidattacks/universe@trunk /sorts --mode ci platform/path/to/repositoryCI mode needs a YAML configuration file.
The file defines how Sorts handles commits.
By default,
Sorts searches for sorts_config.yaml in the root directory of your repository.
To use a different file path,
add the --config flag.
For more information on CI mode, see Use the tool in your CI/CD pipeline.
At this time, CI mode works only on the GitLab platform.
Repository path
In Repo mode and in CI mode, give the absolute path to your repository. This can be a local path or the platform-specific path in your CI/CD pipeline.
Use the tool as a standalone app
-
Make sure that your system has these tools:
-
Run Sorts:
m gitlab:fluidattacks/universe@trunk /sortsAdd the
--helpflag to learn more about what Sorts can do.The primary Sorts function analyzes a repository. It writes a file with the file names and the probability that each file is vulnerable. Use this command:
m gitlab:fluidattacks/universe@trunk /sorts /path/to/repository -
Optionally, set the output type with the
--outflag.When the analysis completes, Sorts makes an output file (JSON or CSV). The file lists all the files in the repository with their vulnerability probabilities.
Use the tool in your CI/CD pipeline
A Makes container is available in the container registry. With it, you can run Sorts on each service that supports containers, which includes most CI/CD providers. You can then use the results to start the actions that you want. The sections below explain how to use it with different CI/CD providers.
GitHub
# .github/workflows/dev.yml
name: Makes CI
on: [push, pull_request]
jobs:
sorts:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@f095bcc56b7c2baf48f3ac70d6d6782f4f553222
- uses: docker://ghcr.io/fluidattacks/makes:latest
name: sorts
with:
args: m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repositoryGitLab
# .gitlab-ci.yml
/sorts:
image: ghcr.io/fluidattacks/makes:latest
script:
- m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repositorySorts includes a built-in function, at this time only on GitLab, for your merge request pipeline. It assigns more approvers when the mean risk of the commit exceeds a given value. Learn more in the Specifications for the CI/CD mode.
Travis
# .travis.yml
os: linux
language: nix
nix: 2.3.12
install: nix-env -if https://github.com/fluidattacks/makes/archive/23.06.tar.gz
jobs:
include:
- script: m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repositorySpecifications for the CI/CD mode
The CI/CD mode of Sorts analyzes a commit pushed to a repository. It checks the probability that each file in the commit is vulnerable. From the mean vulnerability probability of all the files in the commit, Sorts can update the rules to merge the commit into the main branch. Thus the team examines the risky files with the rules that you set.
To use this mode,
you need a configuration file that defines the behavior of Sorts.
By default,
Sorts searches for a file called sorts_config.yaml
in the root of your repository.
You can also give the file path with the --config flag.
The file must be in YAML format.
This is an example of a correct configuration file:
ci:
enable: true
max_risk: 70
platform: gitlab
required_approvals: 2
approvers: ["user-1", "user-2"]
token: ENV_VAR_CONTAINING_API_TOKENThe function of each parameter:
enable: Turns Sorts on or off in your pipelinemax_risk: The maximum threshold for the mean risk of the commit. Above it, more approvers are necessaryplatform: Your development platform (at this time, onlygitlab)required_approvals: The number of approvals necessary when the risk of a commit exceedsmax_riskapprovers: A list of users who can approve high-risk commits (empty: each developer can approve)token: An environment variable with an API token. Sorts uses it to change the approval rules
Do not write the token directly in the configuration file. That exposes sensitive information in your source code. Sorts works only with the name of the environment variable that contains the token, not with the token itself.
Make the configuration file and put it in your repository. Then use the Fluid Attacks Makes container and the Sorts CI mode in your pipeline. This is an example for GitLab:
# .gitlab-ci.yml
/sorts:
image: ghcr.io/fluidattacks/makes:latest
script:
- m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repositoryWhen someone makes a merge request, Sorts adjusts the necessary approvals from the risk of the commit and your configuration.
Use the tool as a Docker container
To use Sorts as a container, you need only Docker. Then run this command:
docker run -v <path/to/repository>:repo/<repository> ghcr.io/fluidattacks/makes:latest m gitlab:fluidattacks/universe@trunk /sorts /repo/<repository>Replace <path/to/repository> with the absolute path to your repository.
Replace <repository> with the name of the repository.
This command downloads the necessary image. It mounts your repository, runs Sorts, and makes an output file (JSON or CSV).
Introduction to Sorts
Learn about Sorts, the Fluid Attacks AI tool for prioritizing files in your software according to their likelihood of having vulnerabilities.
Connection mechanisms
Fluid Attacks offers three secure connectivity options: Cloud, Egress, and Connector (ZTNA), ensuring safe access to your resources. Learn their benefits.