CI & Automation

The supported self-managed Scan-only flow with SHIPMOOR_TOKEN.

3 articles

Articles

Emit SARIF from a Shipmoor scan, upload it into GitHub code scanning, and handle the exit-code contract (exit 1 means the gate fired, not an error) so findings still reach the Security tab.

Read article

GitHub Actions

22 hours ago

Authorize Shipmoor Scan with SHIPMOOR_TOKEN, run the local Scan in GitHub Actions, and optionally upload SARIF to code scanning.

Read article

CI overview

22 hours ago

Run the currently supported self-managed Shipmoor CI flow: local Scan with a scan-scoped SHIPMOOR_TOKEN and optional SARIF upload.

Read article