SARIF & code scanning
2 weeks agoEmit SARIF from a Shipmoor scan, upload it into GitHub code scanning, and handle the exit-code contract (exit 1 means the gate fired, not an error) so findings still reach the Security tab.
Read articleExplore our comprehensive guides and tutorials for CI & Automation. Learn how to optimize your workflow and get the most out of Shipmoor.
Emit SARIF from a Shipmoor scan, upload it into GitHub code scanning, and handle the exit-code contract (exit 1 means the gate fired, not an error) so findings still reach the Security tab.
Read articleRun Shipmoor as a local CI gate in GitHub Actions and upload SARIF to code scanning, using the copy-paste workflow or the composite action.
Read articleRun Shipmoor as a local CI gate: the same scan you run on your laptop, scoped to the change, exiting with a stable code. No source upload, SARIF into code scanning, and Claim Check available as advisory or a gate you opt into.
Read article