How to add SARIF to GitHub Actions
Generate SARIF from a scanner, upload it in GitHub Actions, and keep pull-request security gates deterministic.
radar scan . --quickThe useful pattern
A practical GitHub Actions scanner should run on pull requests, choose a fail-on threshold, publish SARIF, and keep the reviewer comment short.
radar scan . --format sarif --fail-on highGuide
Evidence to inspect
Use “How to add SARIF to GitHub Actions” as the scope for this decision: verify the input, finding detail, workflow handoff, and product boundary before you install or buy.
CriterionEvidence to inspectBoundary
Input scopeSelected files, configuration, scan mode, and enabled rules.Only included paths and configured checks are evaluated.
Finding detailFile, line, rule ID, severity, explanation, and repair direction.Illustrative output is not a result from your repository.
Workflow handoffLocal result, report format, agent context, and optional CI signal.Enable exports or CI only when the workflow needs them.
Decision fitUse the same criteria on a real repository before choosing a plan or tool.No universal winner or guaranteed outcome is claimed.
Official source
Primary sources
Validate the workflow on your own code.
Apply this page’s evidence to one real repository. For “How to add SARIF to GitHub Actions”, confirm which finding is produced, whether the proposed next step is reproducible, and where local scanning, reports, agents, or CI should stop or expand.