Sorts user guide

Last updated: Sep 30, 2026


This page explains how to configure and use Sorts. Sorts is the Fluid Attacks tool that assesses the vulnerability probability of the files in a code repository.

CLI structure

The Sorts command-line interface (CLI) has this structure:

sorts [OPTIONS] REPOSITORY_PATH

With the options, you analyze repositories or commits and set the output format.

Repo mode

Repo mode analyzes one repository. It makes a file with the vulnerability probability of each file. To use Repo mode, add the --mode flag with the repo argument.

Example:

m gitlab:fluidattacks/universe@trunk /sorts --mode repo path/to/repository

CI mode

CI mode integrates Sorts into your CI/CD pipeline. Use it in the phase where reviewers approve commits before the merge. Sorts checks the mean risk of a commit. It then adjusts the necessary approvers with the rules of a configuration file. To use CI mode, add the --mode flag with the ci argument.

Example:

m gitlab:fluidattacks/universe@trunk /sorts --mode ci platform/path/to/repository

CI mode needs a YAML configuration file. The file defines how Sorts handles commits. By default, Sorts searches for sorts_config.yaml in the root directory of your repository. To use a different file path, add the --config flag.

For more information on CI mode, see Use the tool in your CI/CD pipeline.

Repository path

In Repo mode and in CI mode, give the absolute path to your repository. This can be a local path or the platform-specific path in your CI/CD pipeline.

Use the tool as a standalone app

  1. Make sure that your system has these tools:

  2. Run Sorts:

    m gitlab:fluidattacks/universe@trunk /sorts

    The primary Sorts function analyzes a repository. It writes a file with the file names and the probability that each file is vulnerable. Use this command:

    m gitlab:fluidattacks/universe@trunk /sorts /path/to/repository
  3. Optionally, set the output type with the --out flag.

    When the analysis completes, Sorts makes an output file (JSON or CSV). The file lists all the files in the repository with their vulnerability probabilities.

Use the tool in your CI/CD pipeline

A Makes container is available in the container registry. With it, you can run Sorts on each service that supports containers, which includes most CI/CD providers. You can then use the results to start the actions that you want. The sections below explain how to use it with different CI/CD providers.

GitHub

# .github/workflows/dev.yml
name: Makes CI
on: [push, pull_request]
jobs:
   sorts:
      runs-on: ubuntu-latest
      steps:
         - uses: actions/checkout@f095bcc56b7c2baf48f3ac70d6d6782f4f553222
         - uses: docker://ghcr.io/fluidattacks/makes:latest
         name: sorts
         with:
            args: m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repository

GitLab

# .gitlab-ci.yml
/sorts:
  image: ghcr.io/fluidattacks/makes:latest
  script:
    - m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repository

Travis

# .travis.yml
os: linux
language: nix
nix: 2.3.12
install: nix-env -if https://github.com/fluidattacks/makes/archive/23.06.tar.gz
jobs:
  include:
    - script: m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repository

Specifications for the CI/CD mode

The CI/CD mode of Sorts analyzes a commit pushed to a repository. It checks the probability that each file in the commit is vulnerable. From the mean vulnerability probability of all the files in the commit, Sorts can update the rules to merge the commit into the main branch. Thus the team examines the risky files with the rules that you set.

To use this mode, you need a configuration file that defines the behavior of Sorts. By default, Sorts searches for a file called sorts_config.yaml in the root of your repository. You can also give the file path with the --config flag. The file must be in YAML format. This is an example of a correct configuration file:

ci:
  enable: true
  max_risk: 70
  platform: gitlab
  required_approvals: 2
  approvers: ["user-1", "user-2"]
  token: ENV_VAR_CONTAINING_API_TOKEN

The function of each parameter:

  • enable: Turns Sorts on or off in your pipeline
  • max_risk: The maximum threshold for the mean risk of the commit. Above it, more approvers are necessary
  • platform: Your development platform (at this time, only gitlab)
  • required_approvals: The number of approvals necessary when the risk of a commit exceeds max_risk
  • approvers: A list of users who can approve high-risk commits (empty: each developer can approve)
  • token: An environment variable with an API token. Sorts uses it to change the approval rules

Make the configuration file and put it in your repository. Then use the Fluid Attacks Makes container and the Sorts CI mode in your pipeline. This is an example for GitLab:

# .gitlab-ci.yml
/sorts:
  image: ghcr.io/fluidattacks/makes:latest
  script:
    - m gitlab:fluidattacks/universe@trunk /sorts /platform/path/to/repository

When someone makes a merge request, Sorts adjusts the necessary approvals from the risk of the commit and your configuration.

Use the tool as a Docker container

To use Sorts as a container, you need only Docker. Then run this command:

docker run -v <path/to/repository>:repo/<repository> ghcr.io/fluidattacks/makes:latest m gitlab:fluidattacks/universe@trunk /sorts /repo/<repository>

Replace <path/to/repository> with the absolute path to your repository. Replace <repository> with the name of the repository.

This command downloads the necessary image. It mounts your repository, runs Sorts, and makes an output file (JSON or CSV).

On this page