SARIF & code scanning
22 hours agoEmit SARIF from a Shipmoor scan, upload it into GitHub code scanning, and handle the exit-code contract (exit 1 means the gate fired, not an error) so findings still reach the Security tab.
Read articleThe supported self-managed Scan-only flow with SHIPMOOR_TOKEN.
Emit SARIF from a Shipmoor scan, upload it into GitHub code scanning, and handle the exit-code contract (exit 1 means the gate fired, not an error) so findings still reach the Security tab.
Read articleAuthorize Shipmoor Scan with SHIPMOOR_TOKEN, run the local Scan in GitHub Actions, and optionally upload SARIF to code scanning.
Read articleRun the currently supported self-managed Shipmoor CI flow: local Scan with a scan-scoped SHIPMOOR_TOKEN and optional SARIF upload.
Read article