What it is
The SafeWeave GitHub Action runs a SafeWeave scan inside your GitHub Actions workflow and can fail the build when it finds serious problems.
If you've connected a repository to SafeWeave, you already get a check on every push and pull request (see GitHub checks). The Action is for when you want the scan in your own workflow too, for example to upload results to GitHub code scanning.
Who gets it
Everyone. Add your license key to get every scanner your plan includes.
How to use it
- In your repository on GitHub, go to Settings → Secrets and variables → Actions and add a secret named
SAFEWEAVE_LICENSE_KEYwith your license key. - Add
.github/workflows/safeweave.yml:
name: SafeWeave
on: [push, pull_request]
jobs:
scan:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v4
- uses: nickfluxk/safeweave-action@v1
id: safeweave
with:
license-key: ${{ secrets.SAFEWEAVE_LICENSE_KEY }}
fail-on: high
- uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: ${{ steps.safeweave.outputs.sarif-file }}
Options
| Input | Default | What it does |
|---|---|---|
fail-on |
high |
Fail when a finding at this severity or above exists: critical, high, medium, or none to never fail. |
format |
sarif |
json, sarif or text. |
directory |
. |
The folder to scan. |
license-key |
none | Your license key, from a secret. |
scanners |
all on your plan | A comma-separated list of scanners to run. |
The Action also outputs findings-count, score and sarif-file for later steps.
What you'll see
The workflow run passes or fails, and with the upload step, findings appear in your repository's Security → Code scanning tab.
If something goes wrong
- Fewer scanners than expected: check the
SAFEWEAVE_LICENSE_KEYsecret holds your current key. - The upload step fails with a permissions error: add the
permissionsblock shown above.