Repository navigation
Two ways to get the findings in front of people instead of in a log.
A GitHub Action. One step runs the engines against your checkout, writes a findings table to the job summary and fails the step on a finding:
- id: skills
uses: NovaCode37/claude-security-skills@v1
with:
skills: secret-scanner,sast-lite,dockerfile-scan
- uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: ${{ steps.skills.outputs.sarif-dir }}Inputs reach the scanner as environment variables, not interpolated into a shell line, so a crafted input cannot inject a command.
SARIF output. --sarif on secret-scanner and sast-lite prints SARIF 2.1.0, validated against the official schema in the tests. Uploaded, findings show up in the Security tab and on the exact line of the pull request diff, ranked by severity. The secret-scanner SARIF never contains the secret or the line it is on, only file, line and column, because that file goes to GitHub.
Fixed: sast-lite no longer reports platform.system() as a high-severity shell call, which failed builds that only check the OS, and no longer flags hashlib.md5(..., usedforsecurity=False).
@v1 follows compatible releases; pin @v1.3.0 or a commit SHA to stay put. 241 tests, offline, Python 3.9 to 3.12 on Linux, macOS and Windows.
Full notes in the changelog.