socket ci
Get feedback on state of the code health in an automated environment
$ socket ci --help
Alias for `socket scan create --report` (creates report and exits with error if unhealthy)
Usage
$ socket ci [options]
Options
--auto-manifest Auto generate manifest files where detected? See autoManifest flag in `socket scan create`
This command is intended to use in CI runs to allow automated systems to
accept or reject a current build. It will use the default org of the
Socket API token. The exit code will be non-zero when the scan does not pass
your security policy.
The --auto-manifest flag does the same as the one from `socket scan create`
but is not enabled by default since the CI is less likely to be set up with
all the necessary dev tooling. Enable it if you want the scan to include
locally generated manifests like for gradle and sbt.
Examples
$ socket ci
$ socket ci --auto-manifest
This is basically an alias to socket scan create --report. It will create a regular scan, wait for the results, generate a report (similar to socket scan report), and give you a "health" check. If the Scan is not "healthy", ie. it has alerts that violate your security or license policy, then the exit code will be non-zero. This should signal your CI environment that the build failed.
Useful to quickly and easily automate Socket checks in your Continuous Integration runs.
How it picks its settings
socket ci takes no target and no flags other than --auto-manifest. It works out the rest on its own:
- Directory: it always scans the current working directory.
- Organization: it uses the default org from your CLI config (set by
socket loginorsocket config set defaultOrg). If none is set, it uses theSOCKET_CLI_ORG_SLUGenvironment variable. Otherwise it uses the first organization your Socket API token has access to. - Repo and branch: it takes the repo name from your
origingit remote and the branch from git. In a detached checkout on GitHub Actions, it uses the branch from the workflow environment. Other CI systems often check out a detached commit too, and there the branch is recorded as the short commit hash. - Pull request: on GitHub Actions pull request runs, it reads the pull request number from
GITHUB_REF. - Report: it checks both your security policy and your license policy and prints the result as JSON. Only alerts with a policy action of
errorare listed. - Alerts page: when the branch is the default branch of the repository, the scan becomes the one shown on your alerts page.
socket ci does not read the socket scan setup defaults in socket.json, and it never runs reachability analysis. With --auto-manifest, it does use the manifest settings that socket manifest setup stores in socket.json (more details). If you need more control, such as --repo, --branch, or --reach, run socket scan create --report instead.
Your Socket API token needs the full-scans:create, full-scans:list, and security-policy:read permissions.
Exit Code Behavior
Code 0
0The CLI will exit with a status code of 0 under the following conditions:
- The command executes successfully without encountering unexpected errors. The report passes your organization security policy and license policy.
Non-Zero Exit Code
The CLI will return a non-zero exit code in the following scenarios:
- The generated report returns
"healthy": false - The current directory has no supported manifest files to scan.
- An unexpected error occurs during execution.
Updated 10 days ago