SARIF & code scanning
18 hours agoHow Shipmoor's SARIF maps into GitHub code scanning, and how the exit-code contract (1 = gate fired, not an error) should be handled in CI.
Read articleExplore our comprehensive guides and tutorials for CI & Automation. Learn how to optimize your workflow and get the most out of Shipmoor.
How Shipmoor's SARIF maps into GitHub code scanning, and how the exit-code contract (1 = gate fired, not an error) should be handled in CI.
Read articleRun Shipmoor as a local CI gate in GitHub Actions and upload SARIF to code scanning — using the copy-paste workflow or the composite action.
Read articleRun Shipmoor as a local CI gate that never uploads source and uploads SARIF to code scanning. The recommended pattern (scan --changed --fail-on), and a note that managed Team CI gates / PR comments are coming soon.
Read article