Scan PRs for security vulnerabilities, code quality issues, and guardrail compliance.
Add to .github/workflows/opsentry.yml:
name: OpSentry
on:
pull_request:
branches: [main]
permissions:
contents: write
pull-requests: write
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: opsight-intelligence/opsentry-action@v1That's it. Every PR gets scanned for secrets, SQL injection, dangerous patterns, code quality, and guardrail compliance.
| Input | Default | Description |
|---|---|---|
scan-type |
all |
security, code-health, governance, or all |
config-path |
'' |
Path to a guardrails.yaml config file |
scan-mode |
changed |
changed (PR files only) or full (all files) |
fail-on |
high |
Not implemented yet -- accepted but ignored; see below |
auto-fix |
true |
Auto-fix safe issues and commit to PR branch |
post-comment |
true |
Post results as a PR comment |
llm-provider |
none |
LLM for docstring generation: bedrock, anthropic, openai, local, none |
fail-onis not implemented yet. The input is accepted but no step reads it, so the action does not fail the check based on finding severity. Do not rely on it as a merge gate.- Outputs are not populated yet.
action.ymldeclaresfindings-count,critical-count,high-countandreport-path, but none of them is set, so they are always empty. Do not reference them from later steps.
| Output | Status |
|---|---|
findings-count |
Declared, not populated |
critical-count |
Declared, not populated |
high-count |
Declared, not populated |
report-path |
Declared, not populated |
- uses: opsight-intelligence/opsentry-action@v1
with:
scan-type: security
fail-on: critical- uses: opsight-intelligence/opsentry-action@v1
with:
scan-mode: full
llm-provider: anthropic
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}The action does not take API keys as inputs. Pass whatever credentials your chosen
llm-provider needs as env: on the step, sourced from repository secrets -- for
example ANTHROPIC_API_KEY for anthropic, the provider's standard API-key variable
for openai, or AWS credentials (for example via aws-actions/configure-aws-credentials)
for bedrock. local and none need no credentials. Never put a key in the workflow
file itself.
This action follows Semantic Versioning. Each release is tagged
vX.Y.Z, and the floating v1 tag always points at the newest v1.x.y release.
- Pin to
@v1to receive backwards-compatible updates automatically - Pin to
@v1.0.1to lock to an exact release
See CHANGELOG.md for the release history.
See CONTRIBUTING.md for the branching model, versioning rules, and what every change is expected to include.