GitHub Action

Add the SafeWeave GitHub Action to scan every push and pull request in your own GitHub workflow.

What it is

The SafeWeave GitHub Action runs a SafeWeave scan inside your GitHub Actions workflow and can fail the build when it finds serious problems.

If you've connected a repository to SafeWeave, you already get a check on every push and pull request (see GitHub checks). The Action is for when you want the scan in your own workflow too, for example to upload results to GitHub code scanning.

Who gets it

Everyone. Add your license key to get every scanner your plan includes.

How to use it

  1. In your repository on GitHub, go to Settings → Secrets and variables → Actions and add a secret named SAFEWEAVE_LICENSE_KEY with your license key.
  2. Add .github/workflows/safeweave.yml:
name: SafeWeave
on: [push, pull_request]
jobs:
  scan:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
    steps:
      - uses: actions/checkout@v4
      - uses: nickfluxk/safeweave-action@v1
        id: safeweave
        with:
          license-key: ${{ secrets.SAFEWEAVE_LICENSE_KEY }}
          fail-on: high
      - uses: github/codeql-action/upload-sarif@v3
        if: always()
        with:
          sarif_file: ${{ steps.safeweave.outputs.sarif-file }}

Options

Input Default What it does
fail-on high Fail when a finding at this severity or above exists: critical, high, medium, or none to never fail.
format sarif json, sarif or text.
directory . The folder to scan.
license-key none Your license key, from a secret.
scanners all on your plan A comma-separated list of scanners to run.

The Action also outputs findings-count, score and sarif-file for later steps.

What you'll see

The workflow run passes or fails, and with the upload step, findings appear in your repository's Security → Code scanning tab.

If something goes wrong

  • Fewer scanners than expected: check the SAFEWEAVE_LICENSE_KEY secret holds your current key.
  • The upload step fails with a permissions error: add the permissions block shown above.