Skip to content

Actions and CI

Pipes and GitHub.

The one command

sentinel check ./data
sentinel check ./data --fail-warn
echo $?

Fails on high or drift. Add --fail-warn to fail on warn too. Best gate for uploads and golden data.

Json for scripts:

sentinel check ./uploads --json > check.json
sentinel verify ./uploads --json > verify.json
sentinel scan ./uploads --json > scan.json

Sarif for code scanning:

sentinel scan . --sarif > results.sarif
sentinel check . --sarif > results.sarif

Upload with github/codeql-action/upload-sarif.

Verify gate

sentinel verify ./data --fail

Exit 1 on changed or deleted. New files do not fail. Good when baseline is committed.

Full workflow

See examples/github-action.yml. Minimal job:

- uses: actions/checkout@v4
- uses: actions/setup-python@v5
  with:
    python-version: "3.12"
- run: pip install -e .
- run: sentinel check . --json > check.json
- uses: actions/upload-artifact@v4
  with:
    name: sentinel-check
    path: check.json

Sarif job:

- run: sentinel scan . --sarif > results.sarif
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: results.sarif

Docs build runs in ci.yml too via mkdocs build --strict.

HTML artifacts

sentinel report ./uploads --out report.html

One offline file. Upload it, link it in PRs.

Pre commit

- repo: local
  hooks:
    - id: sentinel-check
      name: sentinel check
      entry: sentinel check .
      language: system
      pass_filenames: false

Alerts in prod

sentinel watch ./uploads --webhook "$WEBHOOK_URL"

Body is {"text": "title\ndetail"}. Works for Slack and Discord. Add mail via yaml mail_to plus local smtp if you run your own box.