Skip to content

Scanner workflows ​

codebeaver sarif accepts a SARIF report and reports only findings that are new against an optional baseline. Keep scanners in GitHub Actions. The command normalizes a report only when an authenticated CLI user submits it; GitHub's code-scanning upload does not send findings to the Worker.

The CLI accepts files up to 1 MB:

bash
codebeaver sarif \
  --file reports/current.sarif \
  --baseline reports/main.sarif \
  --fail-on warning

--fail-on accepts none, error, warning, or any. It controls the CLI exit status and is separate from GitHub's code-scanning merge rules.

Each recipe uploads SARIF to GitHub code scanning. GitHub branch protection can make the scanner job a merge gate without placing a CLI credential in Actions.

Semgrep ​

yaml
name: Semgrep
on: [pull_request]
jobs:
  scan:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
    steps:
      - uses: actions/checkout@v4
      - run: pipx run semgrep scan --config p/default --sarif --output semgrep.sarif
      - uses: github/codeql-action/upload-sarif@v3
        if: always()
        with:
          sarif_file: semgrep.sarif

Trivy filesystem scan ​

yaml
name: Trivy
on: [pull_request]
jobs:
  scan:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
    steps:
      - uses: actions/checkout@v4
      - uses: aquasecurity/trivy-action@0.33.1
        with:
          scan-type: fs
          format: sarif
          output: trivy.sarif
      - uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: trivy.sarif

CodeQL ​

yaml
name: CodeQL
on: [pull_request]
jobs:
  analyze:
    runs-on: ubuntu-latest
    permissions:
      security-events: write
      contents: read
    steps:
      - uses: actions/checkout@v4
      - uses: github/codeql-action/init@v3
        with:
          languages: javascript-typescript
      - uses: github/codeql-action/autobuild@v3
      - uses: github/codeql-action/analyze@v3

CodeQL uploads SARIF during analyze. Use its required check for merge gating. codebeaver sarif remains useful for an authenticated local comparison against a baseline.

Reusable upload workflow ​

The repository exports .github/workflows/upload-sarif.yml for callers whose SARIF file already exists in the checked-out repository:

yaml
jobs:
  upload:
    uses: codebeaver/codebeaver/.github/workflows/upload-sarif.yml@main
    with:
      sarif_file: reports/results.sarif

GitHub jobs do not share a working directory. A SARIF file generated in another job is not present in the reusable upload job unless it was committed or transferred as an artifact and downloaded there. For ordinary scanner output, upload in the same job as the scan, as the recipes above do.

Deduplication boundary ​

The CLI removes duplicate scanner records with the same SARIF fingerprint, or the same rule, file, line, and message. Keep each scanner's rule ID in SARIF so scanner output stays traceable. Scanner findings are not persisted with review findings or deduplicated against AI findings.

See the CLI guide for local usage and Architecture for the current separation between scanner and AI findings.

Source-available under BUSL-1.1. Self-hosting is free for your organisation.