Documentation
CI/CD integration
GitHub Actions can use the published Cerbi Scanner Action directly. Azure DevOps teams can install the Visual Studio Marketplace extension, and other CI systems can run the same Scanner engine through the CLI. Start report-only, then enable a failure threshold when the team is ready.
GitHub Marketplace — recommended for GitHub Actions
Cerbi Scanner is published in GitHub Marketplace as Zeroshi/cerbi-scanner-action@v1. The Action sets up .NET 10, installs the tested Scanner package, generates JSON/SARIF/Markdown reports, appends the Markdown summary to the job summary, and can optionally upload SARIF to GitHub Code Scanning.
Open Cerbi Logging Governance Scanner in GitHub Marketplace
name: Cerbi Governance Scan
on:
pull_request:
push:
branches: [main]
jobs:
cerbi-scan:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v7
- name: Run Cerbi Scanner
id: cerbi
uses: Zeroshi/cerbi-scanner-action@v1
with:
fail-on: none
upload-sarif: 'true'
- name: Upload Cerbi reports
if: always()
uses: actions/upload-artifact@v7
with:
name: cerbi-scan-results
path: |
${{ steps.cerbi.outputs.json-file }}
${{ steps.cerbi.outputs.sarif-file }}
${{ steps.cerbi.outputs.summary-file }}Add policy: cerbi-policy.yml when the repository carries an explicit policy. For enforcement, change fail-on: none to a supported threshold such as fail-on: high.
GitHub Action privacy defaults
upload-sarif: 'true' is explicitly enabled.Optional CerbiShield evidence upload
Teams using CerbiShield Pro++ AI Logging Governance can explicitly upload scanner evidence to their tenant-hosted CerbiShield endpoint. Keep the token in GitHub Secrets and use the customer's Router or Reporting ingestion URL from the deployment outputs or Admin settings.
- name: Run Cerbi Scanner with CerbiShield evidence upload
uses: Zeroshi/cerbi-scanner-action@v1
with:
upload-to-cerbishield: 'true'
cerbishield-url: ${{ vars.CERBISHIELD_URL }}
cerbishield-token: ${{ secrets.CERBISHIELD_TOKEN }}
app: claims-service
repo: ${{ github.repository }}
branch: ${{ github.ref_name }}
commit: ${{ github.sha }}
build-id: ${{ github.run_id }}Azure DevOps Marketplace — recommended for Azure DevOps teams
The free Azure DevOps extension is currently version 1.2.8. Install it from Visual Studio Marketplace, then use CerbiScan@1 in an existing pipeline. The extension is a pipeline wrapper around the same Scanner CLI and does not implement a separate detection engine.
Install Cerbi Scanner from Visual Studio Marketplace
steps:
- task: UseDotNet@2
displayName: Install .NET 10 SDK
inputs:
packageType: sdk
version: 10.0.x
- task: CerbiScan@1
displayName: Cerbi logging governance scan
inputs:
scanPath: $(Build.SourcesDirectory)
failOn: none
jsonOutput: $(Build.ArtifactStagingDirectory)/cerbi/cerbi-results.json
sarifOutput: $(Build.ArtifactStagingDirectory)/cerbi/cerbi-results.sarif
markdownSummary: $(Build.ArtifactStagingDirectory)/cerbi/cerbi-report.md
publishArtifacts: trueAdd policyPath: $(Build.SourcesDirectory)/cerbi-policy.yml when the repository carries an explicit policy. For a gate, use a supported threshold such as failOn: high or failOn: error.
Why use the Marketplace path?
Optional CerbiShield evidence upload
Upload is disabled unless uploadToCerbiShield is set. Store the token in a secret pipeline variable and point the task at the tenant's CerbiShield ingestion endpoint.
- task: CerbiScan@1
displayName: Cerbi logging governance scan with evidence upload
inputs:
scanPath: $(Build.SourcesDirectory)
failOn: none
uploadToCerbiShield: true
cerbiShieldEndpoint: $(CERBISHIELD_URL)
cerbiShieldToken: $(CERBISHIELD_TOKEN)
cerbiShieldApp: claims-service
cerbiShieldRepo: $(Build.Repository.Name)
cerbiShieldBranch: $(Build.SourceBranchName)
cerbiShieldCommit: $(Build.SourceVersion)
cerbiShieldBuildId: $(Build.BuildId)Generic CI with the local CLI
CI systems without a Cerbi-specific Marketplace integration can install .NET 10 and the global tool, then invoke cerbi-scanner scan directly.
dotnet tool install --global Cerbi.Scanner --version 1.2.2
cerbi-scanner scan \
--path . \
--fail-on none \
--format json --output cerbi-results/cerbi-report.json \
--sarif cerbi-results/cerbi-report.sarif \
--summary cerbi-results/cerbi-summary.md \
--no-snippetsTo upload evidence from a generic CI runner, keep the bearer token in CERBI_TOKEN and opt in with --upload.
export CERBI_TOKEN="***"
cerbi-scanner scan \
--path . \
--fail-on none \
--format json --output cerbi-results/cerbi-report.json \
--summary cerbi-results/cerbi-summary.md \
--no-snippets \
--upload \
--endpoint "$CERBISHIELD_URL" \
--app claims-service \
--repo "$BUILD_REPOSITORY_NAME" \
--branch "$BUILD_SOURCEBRANCHNAME" \
--commit "$BUILD_SOURCEVERSION" \
--build-id "$BUILD_BUILDID"Reports
| Format | Typical use |
|---|---|
| JSON | Automation, parsing, metrics, and archival. |
| SARIF 2.1.0 | Static-analysis and GitHub Code Scanning ingestion. |
| Markdown | Human-readable build, job-summary, and review output. |
| HTML | Local human-readable report output. |
Safe rollout pattern
- Run the GitHub Action, Azure DevOps extension, or local CLI in report-only mode.
- Review false positives, policy gaps, and expected exceptions.
- Commit policy/configuration alongside the application.
- Only then enable the failure threshold your team actually wants to enforce.
Safe CI defaults