CI and the gate

Bring codafort into CI: SARIF into code scanning, a gate with an exit code from your own conditions, and the vet verdict on the PR delta.

SARIF 2.1.0 feeds GitHub code scanning and any tool that reads the format. No step needs the network beyond downloading the binary.

GitHub Actions: the ready-made action

jobs:
  security:
    runs-on: ubuntu-latest
    permissions:
      security-events: write   # SARIF upload
      contents: read
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }     # --git needs history; vet needs the base
      - uses: codafort/gate-action@v1
        with:
          source: '.'
          vet: 'true'                # verdict on the PR delta (default)
          vet-enforce: 'false'       # report-only: never breaks the build (Free)

The action runs engine analyze --format sarif, publishes to code scanning, archives the coda-gate/1 verdict as evidence and runs vet on the delta. By default it only reports and does not break the build. With vet-enforce: 'true', a blocking vet verdict fails the job.

Without the action: the binary directly (GitLab, Jenkins, any CI)

codafort engine analyze --source . --format sarif --output codafort.sarif --progress never
codafort gate --report codafort.json            # exit 0 pass · 1 fail

For GitHub without the action: github/codeql-action/upload-sarif@v3 with sarif_file: codafort.sarif.

The gate

codafort gate reads an envelope and returns an exit code from the conditions in .codafort-gate.yaml. Without the file, it uses the built-in gate:

MetricDefault condition
vulnerabilities> 0 fails
blocker> 0 fails
taint_findings> 0 fails
risk_findings_high> 0 fails

Your own .codafort-gate.yaml replaces the conditions (metrics per severity, kind, tag). engine analyze --fail-on-quality-gate evaluates the same file in the same step. Both commands look for the configuration in the same order: explicit --config > .codafort-gate.yaml in the directory > built-in.

The gate of the counter-signed declaration (the coda-attestation/1 artifact) does not read this file: attest evaluates fixed conditions of the standard (asvs-l*-sast), versioned under reduction_version. See Counter-signed declaration.

PR mode: new code only

codafort engine analyze --source . --git --diff origin/main --format sarif --output codafort.sarif

--git --diff <base> marks is_new on every finding. Combine a loose gate for legacy with a strict one for new code; the dashboard has a "PR mode" toggle.

Pre-commit

codafort scan . && codafort vet

Or, in the agent, the scan_diff tool before every commit (see Inside your AI agent).

Enforcement at scale

Called directly in the pipeline, codafort gate fails the build on any plan. The public action only reports the gate and fails on vet with vet-enforce. The Platform plan adds consolidation of several repositories (engine merge) and the organisation's policy. The counter-signed declaration starts at the Verified plan and signs the same data you measure in the free CI.