VFA Governance Core - CLI for local check.
986
Run vfa-shield Local:
docker run --rm -e TRIVY_INSECURE=true -v "$PWD":/work vitalifyasia/vfa-shield:latest check
CI configuration:
name: VFA Gate (Docker)
on:
pull_request:
branches: [develop, master]
push:
branches: ['feature/**']
workflow_dispatch:
# A new push supersedes the previous run on the same ref.
concurrency:
group: vfa-gate-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
env:
# Pin a released tag (e.g. :1.2.0) instead of :latest so gate results are
# reproducible and a new image cannot break merges without a commit.
VFA_SHIELD_IMAGE: vitalifyasia/vfa-shield:latest
jobs:
vfa-gate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
# ubuntu-latest already ships Docker Engine + the compose v2 plugin,
# so there is nothing to install here.
- name: Docker version
run: docker --version
- name: Pull vfa-shield
run: docker pull "$VFA_SHIELD_IMAGE"
# The project root is mounted at /work (the image's WORKDIR). The CLI reads
# vfa-adapter.yml + vfa-policy.yml from there and writes both scan reports
# back into the workspace. Exit code 1 = a gate failed = this step fails.
- name: Run VFA gate
run: |
docker run --rm \
-v "$PWD":/work \
"$VFA_SHIELD_IMAGE" check
# Useful variants:
# ... check --no-scan # coverage gate only
# ... check --only coverage,secrets # subset of gates
# -e DEMO_COVERAGE=65 ... check # inject a coverage value
# --env-file .env ... check # pass project env to adapter cmds
# --network host ... check # reach services on the runner host
# --user "$(id -u):$(id -g)" -e HOME=/tmp # avoid root-owned files (self-hosted)
- name: Upload reports
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
with:
name: vfa-security-reports
path: |
trivy-report.json
gitleaks-report.json
if-no-files-found: warn
retention-days: 30
Content type
Image
Digest
sha256:3d906f612…
Size
172.8 MB
Last updated
4 days ago
docker pull vitalifyasia/vfa-shield