CI integration
Run the same verification loop on pull requests so the release decision follows the change—not a reviewer’s memory.
1. Pin the published package
npm install --save-dev --save-exact marucheck@0.5.0
npx --no-install maru initCommit package.json, package-lock.json, and the reviewed.maru configuration. The workflow uses npm ci andnpx --no-install, so it cannot drift to an unreviewed CLI version.
2. Generate the pull-request workflow
npx --no-install maru ci init
git diff -- .github/workflows/marucheck.ymlReview and commit the generated workflow. Running maru ci init again is idempotent; if the target file contains custom content, MaruCheck refuses to overwrite it.
3. What the generated job does
- name: Install project dependencies
run: npm ci
- name: Verify changed behavior
run: npx --no-install maru ci verify- Checks out the pull-request revision with read-only permissions.
- Uses Node.js 24 and the committed npm lockfile.
- Runs the same planner, adapters, evidence model, and release gate as local verification.
- Writes a readable GitHub job summary before returning the gate exit code.
- Uploads hidden
.maruevidence even when the gate blocks.
4. Require the gate
After the workflow has run once, add its ProofLayer check to the repository’s branch ruleset if every protected pull request should require MaruCheck. This is a GitHub repository policy; the CLI does not change it automatically.
Evidence and hosted proof
Keep source execution inside the runner. Upload only the artifacts your policy permits, apply a retention period, and avoid placing secrets or raw sensitive payloads in evidence output. To share normalized proof in the dashboard, add the explicit hosted report step separately.
Frequently asked questions
- How do I add MaruCheck to CI?
- Run maru ci init to install a least-privilege GitHub Actions pull-request workflow. The workflow verifies the diff on each pull request and retains the run's evidence even when the gate blocks, so a failed check leaves an artifact reviewers can open rather than only a red mark.
- Does MaruCheck need access to my CI secrets?
- MaruCheck runs inside your own CI runner, so source and secrets stay within the boundary you already trust for builds. Uploading a report to the hosted dashboard is a separate, explicit step authenticated with a project token you issue and can revoke.
Last updated