Distributed binaries

Last updated: Sep 9, 2026


Fluid Attacks provides native binaries for security scanning that run directly on your machine or CI runner without Docker. Each binary is a single self-contained executable that you install once and run anywhere.

BinaryScannerDescription
ssSecret ScanningDetects hardcoded credentials, API keys, and tokens
csContainer ScanningAnalyzes SCA vulnerabilities for Docker images
dast_apiDAST API ScanningScans API endpoints declared in a Postman collection

How it works

All binaries share the same installation model: a one-line installer downloads the pre-compiled binary for your platform and places it in a directory on your PATH.

Each binary supports one or both of these execution modes:

  • Quick scan — pass a path or an image directly on the command line for an immediate scan with no configuration. Available in ss and cs.
  • Config-driven scan — pass a YAML configuration file for full control over paths, output format, and scan behavior. Available in every binary, and the only mode dast_api supports.

Authenticate

Authenticating attributes the scan to your Fluid Attacks group. On a CI runner, every Fluid Attacks scanner authenticates each run with a Group token, supplied either short-lived via OpenID Connect (pass --group; nothing stored) or as a long-lived INTEGRATES_API_TOKEN secret.

Running a binary on your own machine instead? Sign in through your browser once and skip the token.

See Authentication for setup.

Supported platforms

OSArchitecture
Linuxx86_64, aarch64
macOSApple Silicon (arm64)

Installation

Run the one-line installer for the binary you want. By default, it installs to /usr/local/bin. If that directory is not writable (common on macOS), install to a user-owned directory instead:

mkdir -p ~/.local/bin
curl -fsSL <installer-url> | INSTALL_DIR=~/.local/bin sh

Then make sure ~/.local/bin is on your PATH:

echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.zshrc
source ~/.zshrc

See each binary's page for its specific installer URL and platform notes.

Pipeline gating

To block a CI/CD pipeline when vulnerabilities or secrets are found, use strict mode. Every binary enables it from the configuration file:

strict: true

cs and ss also accept --strict on the CLI when scanning without a config:

cs scan --strict alpine:3.17
ss scan /path/to/project --strict

When strict mode is enabled, the scanner exits with code 1 if any findings are detected, which causes most CI/CD systems to mark the job as failed and block the pipeline.

Common troubleshooting

Permission denied

The installer cannot write to /usr/local/bin because it requires root access. Use a user-writable directory instead:

mkdir -p ~/.local/bin
curl -fsSL <installer-url> | INSTALL_DIR=~/.local/bin sh

Then make sure ~/.local/bin is on your PATH:

echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.zshrc
source ~/.zshrc

tar: could not chdir to '/usr/local/bin'

The install directory does not exist or is not accessible. Create it before running the installer:

mkdir -p /usr/local/bin
curl -fsSL <installer-url> | sh

Or use a custom directory:

mkdir -p ~/.local/bin
curl -fsSL <installer-url> | INSTALL_DIR=~/.local/bin sh

<binary>: command not found

The install directory is not on your PATH. Add it:

echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.zshrc
source ~/.zshrc

Replace <installer-url> with the specific URL for the binary you installed (ss, cs or dast_api) and <binary> with its name. See the individual binary pages for their exact installer URLs.

On this page