Skip to content

CI/CD

Install KAEV as a development dependency for reproducible CI runs:

Terminal window
npm install --save-dev @satiroglu/kaev

Add scripts to the analyzed project’s package.json:

{
"scripts": {
"kaev": "kaev check --fail-on high",
"kaev:sarif": "kaev check --format sarif"
}
}
.github/workflows/kaev.yml
name: Kaev
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
jobs:
analyze:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
cache: npm
- run: npm ci
- run: npm run kaev
- name: Run KAEV annotations
run: npx --no-install kaev check --format github --fail-on high

Use the process exit code rather than parsing terminal text. Use --fail-on none when another system will evaluate the generated artifact.