Code Scanning — CI/CD Integration
Add CoreFix code scanning to your existing pipeline with a single step. The scanner runs as a Docker container (corefixhq/cfix) and can be dropped into any job that already checks out your code.
For detailed CLI options, scanner flags, and BYOK model configuration, refer to Docker / Local CLI.
How It Works
- Your pipeline checks out the repository as it normally does.
- Add the CoreFix scan step — it pulls the
corefixhq/cfixDocker image, mounts the workspace, and runs the scanner. - Results are written to an output directory, pushed to the CoreFix dashboard, and optionally emailed.
You can add the CoreFix scan as a standalone workflow file or as a step in an existing job.
Secrets & Permissions
Store sensitive values as secrets in your CI/CD platform.
| Variable | Storage | Description |
|---|---|---|
X_CFIX_API_KEY | Secret (required) | Your CoreFix API key |
GITHUB_TOKEN | Secret | GitHub token for pushing SARIF to GitHub Code Scanning (see below) |
OPENAI_API_KEY | Secret | Only if bringing your own AI model |
GitHub Token for SARIF Upload
You have two options for providing GITHUB_TOKEN:
Option 1 — Use the built-in GITHUB_TOKEN (GitHub Actions only)
GitHub Actions automatically exposes a GITHUB_TOKEN. Add the following permissions to your workflow so it can upload SARIF results:
permissions:
contents: write
packages: write
security-events: write # required to upload SARIF results to code scanningOption 2 — Use a Personal Access Token (PAT)
If you are not using GitHub Actions, or prefer a PAT, create one with Code Scanning — Read and Write access under the token's repository permissions. Store it as a secret in your CI/CD platform.
Supported Platforms
| Platform | Status |
|---|---|
| GitHub Actions | Supported |
| GitLab CI | Supported |
| Jenkins | Supported |
| CircleCI | Supported |
| Travis CI | Coming soon |
| Bitbucket Pipelines | Coming soon |
| Azure DevOps Pipelines | Coming soon |
GitHub Actions
Add secrets in your repository under Settings → Secrets and variables → Actions → New repository secret. See GitHub Actions encrypted secrets for details.
Create .github/workflows/corefix-code-scan.yml:
name: CoreFix Code Security Scan
on:
push:
branches: [main, master]
pull_request:
permissions:
security-events: write
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Run CoreFix Code Scanner
run: |
mkdir -p ${{ github.workspace }}/scan-results
docker run --rm \
-e X_CFIX_API_KEY=${{ secrets.X_CFIX_API_KEY }} \
-e GITHUB_TOKEN=${{ secrets.GITHUB_TOKEN }} \
-v ${{ github.workspace }}:/code \
-v ${{ github.workspace }}/scan-results:/output \
corefixhq/cfix:latest \
--model gpt-4o-mini
- name: Upload scan results
if: always()
uses: actions/upload-artifact@v4
with:
name: corefix-scan-results
path: scan-results/GitLab CI
Add variables in your project under Settings → CI/CD → Variables. Mark X_CFIX_API_KEY as Masked and Protected. See GitLab CI/CD variables for details.
Create or add to .gitlab-ci.yml:
stages:
- security
corefix-code-scan:
stage: security
image: docker:24
services:
- docker:24-dind
variables:
DOCKER_TLS_CERTDIR: "/certs"
before_script:
- mkdir -p scan-results
script:
- |
docker run --rm \
-e X_CFIX_API_KEY=$X_CFIX_API_KEY \
-v $CI_PROJECT_DIR:/code \
-v $CI_PROJECT_DIR/scan-results:/output \
corefixhq/cfix:latest \
--model gpt-4o-mini
artifacts:
when: always
paths:
- scan-results/
expire_in: 7 daysJenkins
Add credentials in Manage Jenkins → Credentials → System → Global credentials as Secret text entries. See Jenkins credentials for details.
Create a Jenkinsfile for a dedicated security scan pipeline:
pipeline {
agent any
stages {
stage('Checkout') {
steps {
checkout scm
}
}
stage('CoreFix Code Scan') {
steps {
withCredentials([
string(credentialsId: 'corefix-api-key', variable: 'X_CFIX_API_KEY')
]) {
sh '''
mkdir -p scan-results
docker run --rm \
-e X_CFIX_API_KEY=${X_CFIX_API_KEY} \
-v ${WORKSPACE}:/code \
-v ${WORKSPACE}/scan-results:/output \
corefixhq/cfix:latest \
--model gpt-4o-mini
'''
}
}
post {
always {
archiveArtifacts artifacts: 'scan-results/**', allowEmptyArchive: true
}
}
}
}
}CircleCI
Add environment variables in your project under Project Settings → Environment Variables. See CircleCI environment variables for details.
Create .circleci/config.yml:
version: 2.1
jobs:
corefix-code-scan:
machine:
image: ubuntu-2204:current
steps:
- checkout
- run:
name: Run CoreFix Code Scanner
command: |
mkdir -p scan-results
docker run --rm \
-e X_CFIX_API_KEY=$X_CFIX_API_KEY \
-v $PWD:/code \
-v $PWD/scan-results:/output \
corefixhq/cfix:latest \
--model gpt-4o-mini
- store_artifacts:
path: scan-results
destination: corefix-scan-results
workflows:
security:
jobs:
- corefix-code-scanUse the
machineexecutor (notdocker) so that Docker-in-Docker is available.
Choosing Scanners
Run specific scanners to keep pipeline time down, or run all for a full audit:
# All scanners (default — omit positional argument)
corefixhq/cfix:latest
# Dependencies only
corefixhq/cfix:latest osv
# Secrets detection + SAST
corefixhq/cfix:latest secrets,sast
# IaC + Kubernetes
corefixhq/cfix:latest iac,k8s
# Full scan, explicit
corefixhq/cfix:latest osv,iac,secrets,k8s,sastComing Soon
Support for the following platforms is in progress:
- Travis CI
- Bitbucket Pipelines
- Azure DevOps Pipelines