openqodex scan on a pull request’s change. It uploads the findings to GitHub code scanning as SARIF. No model is involved: the Action runs the scanners only.
Example workflow
Save this as.github/workflows/openqodex.yml:
fetch-depth: 0fetches the full history. The scan needs the pull request’s base commit, which a shallow checkout does not have.security-events: writelets the Action upload SARIF to code scanning.actions: readis read by the SARIF upload in a private repository.contents: readlets the job check out the code.
Inputs
version: theopenqodexversion to run. The default is the version the Action was released with.upload-sarif:trueorfalse. The default istrue. Set it tofalseto skip the code scanning upload.
What it does
- Sets up Node 22.
- Restores
~/.openqodex/toolsfrom the Actions cache, keyed on the runner and theopenqodexversion. - Runs
npx -y openqodex@<version> doctor --install, which installs every scanner and waits. - Runs
npx -y openqodex@<version> scan --base <pull request base commit> --format sarif. The SARIF goes to a new folder under the runner’s temporary folder, never into the checkout. - Uploads that SARIF to code scanning, when
upload-sarifistrueand the scan wrote a report. - Fails the job when the scan exited 1 or 2.
.openqodex.yaml sets review.block_on_severity and a finding on a changed line meets it. Without that key, the job never fails on findings. A scan that fails for its own reasons exits 2, and the job fails too.
Config
The Action reads.openqodex.yaml from the repository, like every other command. Custom scanners need an approval stored on the machine that runs them. The runner has none, so the Action lists custom scanners as untrusted and skips them.
Pre-commit
The repository also ships a pre-commit hook for the pre-push stage. Add this to.pre-commit-config.yaml:
npx -y openqodex@<version> scan on the commits not yet pushed plus the working tree. It stops the push only when the scan exits 1. A scan that fails for its own reasons never stops the push. The hook needs Node 22, npx and sh on your machine.