Automation

CI integration

Run the same verification loop on pull requests so the release decision follows the change—not a reviewer’s memory.

1. Pin the published package

Terminal
npm install --save-dev --save-exact marucheck@0.5.0
npx --no-install maru init

Commit package.json, package-lock.json, and the reviewed.maru configuration. The workflow uses npm ci andnpx --no-install, so it cannot drift to an unreviewed CLI version.

2. Generate the pull-request workflow

Terminal
npx --no-install maru ci init
git diff -- .github/workflows/marucheck.yml

Review and commit the generated workflow. Running maru ci init again is idempotent; if the target file contains custom content, MaruCheck refuses to overwrite it.

3. What the generated job does

GitHub Actions
- name: Install project dependencies
  run: npm ci

- name: Verify changed behavior
  run: npx --no-install maru ci verify
  1. Checks out the pull-request revision with read-only permissions.
  2. Uses Node.js 24 and the committed npm lockfile.
  3. Runs the same planner, adapters, evidence model, and release gate as local verification.
  4. Writes a readable GitHub job summary before returning the gate exit code.
  5. Uploads hidden .maru evidence even when the gate blocks.

4. Require the gate

After the workflow has run once, add its ProofLayer check to the repository’s branch ruleset if every protected pull request should require MaruCheck. This is a GitHub repository policy; the CLI does not change it automatically.

Evidence and hosted proof

Keep source execution inside the runner. Upload only the artifacts your policy permits, apply a retention period, and avoid placing secrets or raw sensitive payloads in evidence output. To share normalized proof in the dashboard, add the explicit hosted report step separately.

Frequently asked questions

How do I add MaruCheck to CI?
Run maru ci init to install a least-privilege GitHub Actions pull-request workflow. The workflow verifies the diff on each pull request and retains the run's evidence even when the gate blocks, so a failed check leaves an artifact reviewers can open rather than only a red mark.
Does MaruCheck need access to my CI secrets?
MaruCheck runs inside your own CI runner, so source and secrets stay within the boundary you already trust for builds. Uploading a report to the hosted dashboard is a separate, explicit step authenticated with a project token you issue and can revoke.

Last updated