BWorlds CLI

Quickstart

Install the binary, sign in, pick a Build, and read its Audit. Five minutes, nothing charged.

Command JSON

You end this page with the current Audit of one Build in your terminal, the same Audit its Builder sees in the app. Nothing here consumes tokens.

1. Install

The installer detects macOS or Linux, verifies the release checksum, and installs bworlds into $HOME/.local/bin.

curl -fsSLO https://docs.bworlds.co/install.sh
sh install.sh
bworlds --version

Pin BWORLDS_VERSION in automation and set BWORLDS_INSTALL_DIR when you want another directory. Details in Installation and updates.

2. Sign in

If you are operating a Build owned by someone else, ask its Workspace Owner to invite you first from Workspace sharing at https://app.bworlds.co/account/team, and accept the invitation with the identity you will use here. Your own Builds need no invitation.

bworlds auth login

The browser signs you in and the CLI stores the session in your user configuration directory, readable only by you. Check what the server sees:

bworlds auth status
Identity:    Lea Marchand (@lea)
Workspaces:  2
  8f1c2a7e-3b4d-4c5e-9f60-1a2b3c4d5e6f  Lea Marchand  (owner)
  a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d  Atelier Nord  (member)
Builds:      5

3. Pick the Build

bworlds repo list
Operator: @lea  Environment: prod

SLUG        NAME            WORKSPACE     WORKSPACE ID                          LOCAL
storefront  Storefront      Atelier Nord  a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d  -
inventory   Inventory Desk  Atelier Nord  a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d  -

Every Build command takes the slug from this list. Before acting on one, confirm what you are looking at:

bworlds build info storefront
Operator: lea (member)
Workspace: Atelier Nord (a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d)
Build: storefront (3d9e7f10-2b4c-4d8e-9a1f-6c7d8e9f0a1b), builder maxime
Authorized areas: security, operations
Token balance: 1240 tokens
GitHub: connected to atelier-nord/storefront (installation 4821931)

One screen tells you who you are for this Build, whether its Builder connected a repository, how many tokens the Workspace holds, and in which areas the Builder authorized BWorlds to fix code.

4. Read the Audit

bworlds audit show storefront
Results (17 Controls):

FAIL (2):
  app-open-access          FAIL
    Found: Signed-out visitors can reach content identified as private.
    Why:   Requiring a sign-in stops anyone with the link from seeing private information or using paid features.
    Fix:   Require a signed-in session on private pages and redirect other visitors to sign-in.
  privacy-policy           FAIL
    Found: A published privacy policy was not found on the app pages checked.
    Why:   A clear privacy policy tells people what information the app collects and how it is used.
    Fix:   Publish a privacy policy and link it from the footer.

pending (3):
  data-backup              pending
  code-ownership-clean     pending
  version-control          pending

pass (12):
  secrets-exposed          pass
  database-not-public      pass
  https-enabled            pass
  ...

Every failed Control comes with what BWorlds found, why it matters, and how to fix it. This is the Audits screen of the Build in the app, and reading it is free. Pending Controls are still running or wait for the Builder's answer to a question in the app.

Next

On this page