Scanner workflows â
codebeaver sarif accepts a SARIF report and reports only findings that are new against an optional baseline. Keep scanners in GitHub Actions. The command normalizes a report only when an authenticated CLI user submits it; GitHub's code-scanning upload does not send findings to the Worker.
The CLI accepts files up to 1 MB:
codebeaver sarif \
--file reports/current.sarif \
--baseline reports/main.sarif \
--fail-on warning--fail-on accepts none, error, warning, or any. It controls the CLI exit status and is separate from GitHub's code-scanning merge rules.
Each recipe uploads SARIF to GitHub code scanning. GitHub branch protection can make the scanner job a merge gate without placing a CLI credential in Actions.
Semgrep â
name: Semgrep
on: [pull_request]
jobs:
scan:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v4
- run: pipx run semgrep scan --config p/default --sarif --output semgrep.sarif
- uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: semgrep.sarifTrivy filesystem scan â
name: Trivy
on: [pull_request]
jobs:
scan:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v4
- uses: aquasecurity/trivy-action@0.33.1
with:
scan-type: fs
format: sarif
output: trivy.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: trivy.sarifCodeQL â
name: CodeQL
on: [pull_request]
jobs:
analyze:
runs-on: ubuntu-latest
permissions:
security-events: write
contents: read
steps:
- uses: actions/checkout@v4
- uses: github/codeql-action/init@v3
with:
languages: javascript-typescript
- uses: github/codeql-action/autobuild@v3
- uses: github/codeql-action/analyze@v3CodeQL uploads SARIF during analyze. Use its required check for merge gating. codebeaver sarif remains useful for an authenticated local comparison against a baseline.
Reusable upload workflow â
The repository exports .github/workflows/upload-sarif.yml for callers whose SARIF file already exists in the checked-out repository:
jobs:
upload:
uses: codebeaver/codebeaver/.github/workflows/upload-sarif.yml@main
with:
sarif_file: reports/results.sarifGitHub jobs do not share a working directory. A SARIF file generated in another job is not present in the reusable upload job unless it was committed or transferred as an artifact and downloaded there. For ordinary scanner output, upload in the same job as the scan, as the recipes above do.
Deduplication boundary â
The CLI removes duplicate scanner records with the same SARIF fingerprint, or the same rule, file, line, and message. Keep each scanner's rule ID in SARIF so scanner output stays traceable. Scanner findings are not persisted with review findings or deduplicated against AI findings.
See the CLI guide for local usage and Architecture for the current separation between scanner and AI findings.