DocumentationSearch docs
  1. 01Getting started
  2. 02Scanning
  3. 03Checks
  4. 04Services
  5. 05Configuration
  6. 06Ignoring checks
  7. 07CI
  8. 08Agent skill
  9. 09Dashboard
  10. 10Supported stacks

CI

CI

Run Preflight in CI and a pull request can’t merge a launch mistake. --ci turns off prompts, and the exit code fails the step: 2 on an error, 1 on warnings only.

GitHub Actions

With the install script:

- name: Run Preflight
  run: |
    curl -sSL https://preflight.sh/install.sh | sh
    preflight scan --ci

With npm:

- name: Run Preflight
  run: |
    npm install -g @preflightsh/preflight
    preflight scan --ci

With Docker, mounting the checkout at /app:

- name: Run Preflight
  run: docker run -v ${{ github.workspace }}:/app ghcr.io/preflightsh/preflight scan --ci --format json

Failing on errors only

A warning exits 1, which fails a step. To fail only on errors, let 1 through:

- name: Run Preflight
  run: |
    preflight scan --ci || [ $? -eq 1 ]

Keeping a history

Add --publish and each CI run lands on your dashboard, so you can see what changed between deploys. Publishing never fails a build: offline or signed out, the scan still runs and exits as it would have.

Pull requests from forks

The vulnerability check runs the project’s package manager, and project configuration can make a package manager run code. When CI scans a fork’s pull request, add --skip vulnerability. Checks explains why.