CI
CI
Run Preflight in CI and a pull request can’t merge a launch mistake. --ci turns off prompts, and the exit code fails the step: 2 on an error, 1 on warnings only.
GitHub Actions
With the install script:
- name: Run Preflight
run: |
curl -sSL https://preflight.sh/install.sh | sh
preflight scan --ciWith npm:
- name: Run Preflight
run: |
npm install -g @preflightsh/preflight
preflight scan --ciWith Docker, mounting the checkout at /app:
- name: Run Preflight
run: docker run -v ${{ github.workspace }}:/app ghcr.io/preflightsh/preflight scan --ci --format jsonFailing on errors only
A warning exits 1, which fails a step. To fail only on errors, let 1 through:
- name: Run Preflight
run: |
preflight scan --ci || [ $? -eq 1 ]Keeping a history
Add --publish and each CI run lands on your dashboard, so you can see what changed between deploys. Publishing never fails a build: offline or signed out, the scan still runs and exits as it would have.
Pull requests from forks
The vulnerability check runs the project’s package manager, and project configuration can make a package manager run code. When CI scans a fork’s pull request, add --skip vulnerability. Checks explains why.