# GitHub Actions

Check agent instructions on pull requests and pushes, then bring findings into GitHub Code Scanning with SARIF. LintLang can generate the workflow for an existing input in your repository.

## Setup

[Install the CLI](/docs/install), enable Actions for the repository, and choose a committed instruction file or supported directory. From the repository root:

```bash
lintlang init --github --path AGENTS.md
```

Review `.github/workflows/lintlang.yml` before committing it. The generated workflow runs on pull requests and pushes to `main`; adjust the branch if needed. The released initializer pins the **LintLang v0.7.0 Action by immutable commit**, separately from the current CLI package.

The maintained [complete workflow](https://github.com/hermes-labs-ai/lintlang/blob/c0cab00048220286858f227aaf4b13cc043f718b/examples/github-code-scanning.yml) is the reference for adapting scan, artifact, and upload jobs. An existing different workflow is preserved: the initializer will refuse to overwrite it. Use `--force` only after reviewing the changes you intend to replace.

## Verify

```bash
lintlang scan AGENTS.md --fail-on fail
git status --short
```

Inspect the generated YAML's path, triggers, pins, and permissions. The local scan checks your current installed scanner; the Action runs its pinned release. After committing the workflow, verify the scan job and its report artifact in Actions.

## Findings and thresholds

The Action defaults to `fail`: HIGH and CRITICAL findings fail the job. Set `fail-on: review` to include MEDIUM findings. For an advisory workflow, run the CLI without `--fail-on`; `none` is not a supported Action threshold. Input and coverage errors remain nonzero.

For an existing backlog, [create and review a baseline](/docs/baselines), then supply it through the Action's `baseline` input. CI reads the baseline rather than refreshing it.

## Code scanning

Code Scanning requires an eligible repository with the feature enabled. The workflow separates a read-only scan and artifact job from an upload job with `security-events: write`. Uploads are skipped for fork and Dependabot pull requests; their scans and artifact preservation still run.

Verify the upload job and the repository's Code Scanning results separately. A report artifact alone does not confirm ingestion. To generate SARIF locally:

```bash
lintlang scan AGENTS.md --format sarif --fail-on fail > lintlang.sarif
```

Keep report destinations separate from scanned inputs. The [full released guide](https://github.com/hermes-labs-ai/lintlang/blob/c0cab00048220286858f227aaf4b13cc043f718b/docs/github.md) covers path detection, upload eligibility, errors, and removal.

## Next steps

[Review baselines](/docs/baselines) · [Understand outputs](/docs/outputs) · [All integrations](/integrations)

