Skip to main content

What this gives you

A single uses: line that installs agent-guardian, runs a scan, writes SARIF, and uploads it to GitHub Code Scanning. Use this in place of the longhand workflow in GitHub Actions when you want the shortest possible adoption path.

Wire it up

Grant permissions

The calling workflow must grant security-events: write so SARIF upload succeeds, and pull-requests: write so the sticky PR comment can be upserted. Composite actions cannot declare repository-level permissions, so the caller owns this.

Add the action

.github/workflows/agent-guardian.yml

Confirm the run

Open a PR. The scan check appears in the PR conversation, the SARIF artifact is attached to the workflow run, and findings show up under Security → Code scanning keyed by the agentguardian category.

Inputs

Outputs

Severity gates

fail-under gates on the numeric AIVSS floor. The max-* inputs add per-severity ceilings on top of it, AND-combined: the gate fails if AIVSS drops below fail-under or any severity count exceeds its ceiling. The default max-critical: "0" means a single CRITICAL finding fails the build even when the AIVSS still clears the floor.
Set any of these to an empty string ("") to disable that individual ceiling.

Sticky PR comment

When comment is true (default) and the workflow is triggered by a pull_request event, the action runs agent-guardian comment --platform github after the scan. It upserts a single summary comment on the PR — keyed by a hidden HTML marker so re-runs edit the existing comment in place rather than posting a new one on every push. The comment embeds the same fail-under / max-* verdict as the gate, so a green/red comment always matches the CI exit code. The comment step is advisory: if it cannot post (for example a fork PR whose GITHUB_TOKEN lacks write scope) it logs a warning and the job continues — it never changes the scan’s pass/fail outcome. See PR comments for a rendered sample and the marker details.

Sample report

A static reference report generated from a real scan: sample-report.pdf.

When to use the longhand form instead

Use the longhand workflow when you need to:
  • Run on a self-hosted runner without internet access (you supply your own install step).
  • Run the scan inside a services: container that the composite action would not see.
  • Compose multiple scans against the same target across the same job (the composite action assumes one scan per step).