Back to Cerbi Scanner

Documentation

CI/CD integration

GitHub Actions can use the published Cerbi Scanner Action directly. Azure DevOps teams can install the Visual Studio Marketplace extension, and other CI systems can run the same Scanner engine through the CLI. Start report-only, then enable a failure threshold when the team is ready.

GitHub Marketplace — recommended for GitHub Actions

Cerbi Scanner is published in GitHub Marketplace as Zeroshi/cerbi-scanner-action@v1. The Action sets up .NET 10, installs the tested Scanner package, generates JSON/SARIF/Markdown reports, appends the Markdown summary to the job summary, and can optionally upload SARIF to GitHub Code Scanning.

Open Cerbi Logging Governance Scanner in GitHub Marketplace

name: Cerbi Governance Scan

on:
  pull_request:
  push:
    branches: [main]

jobs:
  cerbi-scan:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
    steps:
      - uses: actions/checkout@v7

      - name: Run Cerbi Scanner
        id: cerbi
        uses: Zeroshi/cerbi-scanner-action@v1
        with:
          fail-on: none
          upload-sarif: 'true'

      - name: Upload Cerbi reports
        if: always()
        uses: actions/upload-artifact@v7
        with:
          name: cerbi-scan-results
          path: |
            ${{ steps.cerbi.outputs.json-file }}
            ${{ steps.cerbi.outputs.sarif-file }}
            ${{ steps.cerbi.outputs.summary-file }}

Add policy: cerbi-policy.yml when the repository carries an explicit policy. For enforcement, change fail-on: none to a supported threshold such as fail-on: high.

GitHub Action privacy defaults

Source is scanned on the GitHub Actions runner. The Action does not upload source code or findings to Cerbi by default, source snippets are disabled by default, and GitHub receives SARIF only when upload-sarif: 'true' is explicitly enabled.

Optional CerbiShield evidence upload

Teams using CerbiShield Pro++ AI Logging Governance can explicitly upload scanner evidence to their tenant-hosted CerbiShield endpoint. Keep the token in GitHub Secrets and use the customer's Router or Reporting ingestion URL from the deployment outputs or Admin settings.

      - name: Run Cerbi Scanner with CerbiShield evidence upload
        uses: Zeroshi/cerbi-scanner-action@v1
        with:
          upload-to-cerbishield: 'true'
          cerbishield-url: ${{ vars.CERBISHIELD_URL }}
          cerbishield-token: ${{ secrets.CERBISHIELD_TOKEN }}
          app: claims-service
          repo: ${{ github.repository }}
          branch: ${{ github.ref_name }}
          commit: ${{ github.sha }}
          build-id: ${{ github.run_id }}

Azure DevOps Marketplace — recommended for Azure DevOps teams

The free Azure DevOps extension is currently version 1.2.8. Install it from Visual Studio Marketplace, then use CerbiScan@1 in an existing pipeline. The extension is a pipeline wrapper around the same Scanner CLI and does not implement a separate detection engine.

Install Cerbi Scanner from Visual Studio Marketplace

steps:
- task: UseDotNet@2
  displayName: Install .NET 10 SDK
  inputs:
    packageType: sdk
    version: 10.0.x

- task: CerbiScan@1
  displayName: Cerbi logging governance scan
  inputs:
    scanPath: $(Build.SourcesDirectory)
    failOn: none
    jsonOutput: $(Build.ArtifactStagingDirectory)/cerbi/cerbi-results.json
    sarifOutput: $(Build.ArtifactStagingDirectory)/cerbi/cerbi-results.sarif
    markdownSummary: $(Build.ArtifactStagingDirectory)/cerbi/cerbi-report.md
    publishArtifacts: true

Add policyPath: $(Build.SourcesDirectory)/cerbi-policy.yml when the repository carries an explicit policy. For a gate, use a supported threshold such as failOn: high or failOn: error.

Why use the Marketplace path?

For Azure DevOps teams, the Marketplace extension provides the familiar organization-level install and pipeline-task experience while keeping execution on the customer's existing build agent. It is a distribution option, not a different Scanner engine or a Microsoft endorsement of Cerbi.

Optional CerbiShield evidence upload

Upload is disabled unless uploadToCerbiShield is set. Store the token in a secret pipeline variable and point the task at the tenant's CerbiShield ingestion endpoint.

- task: CerbiScan@1
  displayName: Cerbi logging governance scan with evidence upload
  inputs:
    scanPath: $(Build.SourcesDirectory)
    failOn: none
    uploadToCerbiShield: true
    cerbiShieldEndpoint: $(CERBISHIELD_URL)
    cerbiShieldToken: $(CERBISHIELD_TOKEN)
    cerbiShieldApp: claims-service
    cerbiShieldRepo: $(Build.Repository.Name)
    cerbiShieldBranch: $(Build.SourceBranchName)
    cerbiShieldCommit: $(Build.SourceVersion)
    cerbiShieldBuildId: $(Build.BuildId)

Generic CI with the local CLI

CI systems without a Cerbi-specific Marketplace integration can install .NET 10 and the global tool, then invoke cerbi-scanner scan directly.

dotnet tool install --global Cerbi.Scanner --version 1.2.2

cerbi-scanner scan \
  --path . \
  --fail-on none \
  --format json --output cerbi-results/cerbi-report.json \
  --sarif cerbi-results/cerbi-report.sarif \
  --summary cerbi-results/cerbi-summary.md \
  --no-snippets

To upload evidence from a generic CI runner, keep the bearer token in CERBI_TOKEN and opt in with --upload.

export CERBI_TOKEN="***"

cerbi-scanner scan \
  --path . \
  --fail-on none \
  --format json --output cerbi-results/cerbi-report.json \
  --summary cerbi-results/cerbi-summary.md \
  --no-snippets \
  --upload \
  --endpoint "$CERBISHIELD_URL" \
  --app claims-service \
  --repo "$BUILD_REPOSITORY_NAME" \
  --branch "$BUILD_SOURCEBRANCHNAME" \
  --commit "$BUILD_SOURCEVERSION" \
  --build-id "$BUILD_BUILDID"

Reports

FormatTypical use
JSONAutomation, parsing, metrics, and archival.
SARIF 2.1.0Static-analysis and GitHub Code Scanning ingestion.
MarkdownHuman-readable build, job-summary, and review output.
HTMLLocal human-readable report output.

Safe rollout pattern

  1. Run the GitHub Action, Azure DevOps extension, or local CLI in report-only mode.
  2. Review false positives, policy gaps, and expected exceptions.
  3. Commit policy/configuration alongside the application.
  4. Only then enable the failure threshold your team actually wants to enforce.

Safe CI defaults

The GitHub Action and Azure DevOps wrapper keep source snippets disabled by default for shared CI artifacts, and CerbiShield upload is disabled by default. See Security & privacy for the data-flow details.
NEXTChoose your next proof

Review a Scanner finding or logging requirement against your existing controls. If a recurring gap remains, scope one CerbiShield workload, policy, evaluation window, and evidence review.

One initial workload/Customer-hosted in Azure/Existing destinations remain
Scanner CI/CD Integration — Cerbi Docs