Docs / INTEGRATIONS
INTEGRATIONS
CI/CD Integration
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex is designed to run in automated pipelines. The check command provides exit codes suitable for gate checks, and output formats like SARIF integrate directly with code scanning platforms.
GitHub Actions
name: Korthex Crypto Scan on: [push, pull_request] jobs: scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 # Signature-verified install: the script pins the Ed25519 release key and # aborts (non-zero, nothing written) if the manifest or artifact does not # verify against it. - name: Install Korthex run: curl -fsSL https://api.korthex.flowence.cc/api/version/install.sh | bash - name: Run Scan run: korthex check . --fail-on high --format sarif --output results.sarif - name: Upload SARIF if: always() uses: github/codeql-action/upload-sarif@v3 with: sarif_file: results.sarif
GitLab CI
korthex-scan: image: ubuntu:22.04 stage: test script: # ubuntu:22.04 is a minimal image: curl and CA certificates are not preinstalled. - apt-get update -qq && apt-get install -y -qq curl ca-certificates - curl -fsSL https://api.korthex.flowence.cc/api/version/install.sh | bash - export PATH="$HOME/.korthex/bin:$PATH" # --format gitlab-cq is what the Code Quality widget parses. --format json # emits the check SUMMARY, which GitLab accepts and then renders as nothing. - korthex check . --fail-on high --format gitlab-cq --output gl-korthex-report.json artifacts: when: always reports: codequality: gl-korthex-report.json paths: - gl-korthex-report.json
Azure DevOps
- task: Bash@3 displayName: 'Korthex Crypto Scan' inputs: targetType: 'inline' script: | curl -fsSL https://api.korthex.flowence.cc/api/version/install.sh | bash korthex check . --fail-on high --format sarif --output $(Build.ArtifactStagingDirectory)/korthex.sarif - task: PublishBuildArtifacts@1 inputs: PathtoPublish: '$(Build.ArtifactStagingDirectory)/korthex.sarif' ArtifactName: 'KorthexResults'
Jenkins
pipeline { agent any stages { stage('Korthex Scan') { steps { // Without this the agent has no korthex on PATH. sh 'curl -fsSL https://api.korthex.flowence.cc/api/version/install.sh | bash' sh 'export PATH="$HOME/.korthex/bin:$PATH" && korthex check . --fail-on high --format sarif --output korthex.sarif' } post { always { archiveArtifacts artifacts: 'korthex.sarif' } } } } }