Basic Workflow
.github/workflows/security.yml
Required Secrets
Add these secrets to your repository:Exit Codes
The workflow fails when vulnerabilities are found:
Add
--fail-on high (or critical, medium, low) to fail only on findings at or above that severity. Lower findings still appear in the report, so a passing run is not necessarily finding-free.
Scan Modes for CI
For pull_request workflows, Strix automatically uses changed-files diff-scope in CI/headless runs. If diff resolution fails, ensure full history is fetched (
fetch-depth: 0) or set --diff-base.