socket ci

Get feedback on state of the code health in an automated environment

$ socket ci --help

  Alias for `socket scan create --report` (creates report and exits with error if unhealthy)

  Usage
    $ socket ci [options]

  Options
    --auto-manifest     Auto generate manifest files where detected? See autoManifest flag in `socket scan create`

  This command is intended to use in CI runs to allow automated systems to
  accept or reject a current build. It will use the default org of the
  Socket API token. The exit code will be non-zero when the scan does not pass
  your security policy.

  The --auto-manifest flag does the same as the one from `socket scan create`
  but is not enabled by default since the CI is less likely to be set up with
  all the necessary dev tooling. Enable it if you want the scan to include
  locally generated manifests like for gradle and sbt.

  Examples
    $ socket ci
    $ socket ci --auto-manifest

This is basically an alias to socket scan create --report. It will create a regular scan, wait for the results, generate a report (similar to socket scan report), and give you a "health" check. If the Scan is not "healthy", ie. it has alerts that violate your security or license policy, then the exit code will be non-zero. This should signal your CI environment that the build failed.

Useful to quickly and easily automate Socket checks in your Continuous Integration runs.

How it picks its settings

socket ci takes no target and no flags other than --auto-manifest. It works out the rest on its own:

  • Directory: it always scans the current working directory.
  • Organization: it uses the default org from your CLI config (set by socket login or socket config set defaultOrg). If none is set, it uses the SOCKET_CLI_ORG_SLUG environment variable. Otherwise it uses the first organization your Socket API token has access to.
  • Repo and branch: it takes the repo name from your origin git remote and the branch from git. In a detached checkout on GitHub Actions, it uses the branch from the workflow environment. Other CI systems often check out a detached commit too, and there the branch is recorded as the short commit hash.
  • Pull request: on GitHub Actions pull request runs, it reads the pull request number from GITHUB_REF.
  • Report: it checks both your security policy and your license policy and prints the result as JSON. Only alerts with a policy action of error are listed.
  • Alerts page: when the branch is the default branch of the repository, the scan becomes the one shown on your alerts page.

socket ci does not read the socket scan setup defaults in socket.json, and it never runs reachability analysis. With --auto-manifest, it does use the manifest settings that socket manifest setup stores in socket.json (more details). If you need more control, such as --repo, --branch, or --reach, run socket scan create --report instead.

Your Socket API token needs the full-scans:create, full-scans:list, and security-policy:read permissions.

Exit Code Behavior

Code 0

The CLI will exit with a status code of 0 under the following conditions:

  • The command executes successfully without encountering unexpected errors. The report passes your organization security policy and license policy.

Non-Zero Exit Code

The CLI will return a non-zero exit code in the following scenarios:

  • The generated report returns "healthy": false
  • The current directory has no supported manifest files to scan.
  • An unexpected error occurs during execution.

Did this page help you?