CI/CD
Install KAEV as a development dependency for reproducible CI runs:
npm install --save-dev @satiroglu/kaevAdd scripts to the analyzed project’s package.json:
{ "scripts": { "kaev": "kaev check --fail-on high", "kaev:sarif": "kaev check --format sarif" }}GitHub Actions quality gate
Section titled “GitHub Actions quality gate”name: Kaev
on: pull_request: push: branches: [main]
permissions: contents: read
jobs: analyze: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: npm - run: npm ci - run: npm run kaevWorkflow annotations
Section titled “Workflow annotations”- name: Run KAEV annotations run: npx --no-install kaev check --format github --fail-on highUse the process exit code rather than parsing terminal text. Use --fail-on none when another system will evaluate the generated artifact.