Skip to main content
Run a pentest from GitHub Actions and fail the check if it discovers critical vulnerabilities. This example runs nightly or on demand.

1. Configure credentials and targets

Add these values to your GitHub repository: The CLI authenticates with the API key automatically. See Targets if you haven’t submitted your target for approval.

2. Add the pentest script

Create scripts/pentest.sh:
antigen run waits until testing completes. --quiet suppresses activity, and --json writes the vulnerabilities to results.json. The last command checks every vulnerability. It exits successfully if none are critical and fails otherwise. If the run itself fails or stops, the script exits before checking results. To include your repository’s skills, add --skills ./skills/ to the run command.

3. Configure GitHub Actions

Create .github/workflows/security.yml:
The schedule runs at 02:00 UTC. You can also start it manually from the repository’s Actions tab.

Work with the results

The workflow saves results.json as a job artifact. You can download it to inspect the vulnerabilities or process it with other tools:
Vulnerabilities and evidence are also available in the Antigen platform. For testing after a production deployment, see the SDK example.