-
Notifications
You must be signed in to change notification settings - Fork 2
CICD Integration
serbanb11 edited this page Apr 4, 2026
·
1 revision
| Code | Meaning |
|---|---|
| 0 | All checks passed (or only non-critical failures) |
| 1 | Non-critical failures exist |
| 2 | Critical failures exist (with --fail-on-critical) |
gws-auditor --fail-on-critical --config config.yaml -f json -qThe -q flag suppresses output except errors, and -f json generates a machine-readable report.
- name: Run GWS Security Audit
run: |
gws-auditor --fail-on-critical --config config.yaml -f json -q
env:
GOOGLE_APPLICATION_CREDENTIALS: ${{ secrets.GWS_SA_KEY_PATH }}For pipelines without Python:
- name: Download gws-auditor
run: |
curl -L -o gws-auditor https://github.com/your-org/argussec/releases/latest/download/gws-auditor-linux-amd64
chmod +x gws-auditor
- name: Run audit
run: ./gws-auditor --fail-on-critical -f json -qUpload the JSON report as a pipeline artifact for historical tracking:
- uses: actions/upload-artifact@v4
with:
name: gws-audit-report
path: reports/*.json