Last updated
Manually marking alerts as "False Positive" or "Ignored" in your scanner's UI.
Best for: Small teams or one-off exceptions.
Regardless of the CI system, the golden rule of Seal CLI integration is Timing.
Timing Rule: The Seal CLI must run immediately after packages are fetched/installed, but before the project is compiled or built.
Standard CI (Jenkins, GitLab CI, CircleCI): Add a shell step to download the CLI and run the seal fix command after your dependency fetch step (e.g., after npm install or go mod download).
GitHub Actions: Seal Security provides a dedicated GitHub Action. Simply add it to your workflow file .github/workflows/main.yml.
Docker: Add the CLI run command directly into your Dockerfile (often strictly for the build stage to keep the final image slim).
Last updated