Skip to content

GitHub Action

GitHub Action

Scan a full repository on push or schedule with Pervaziv AI Code Review.

The GitHub Action performs full-repository security analysis on a push or schedule. It publishes a GitHub Actions summary, uploads alerts to Security → Code scanning, links the detailed Pervaziv Console report, and can create a pull request with suggested fixes.

Use the Marketplace button above and add the workflow below after connecting the repository to Pervaziv. Choose the branches and schedule for the assessment; the GitHub App provides the separate pull-request review experience.

  1. Create or sign in to a Pervaziv account with a Premium or higher plan.
  2. Add the GitHub repository as a project in the Pervaziv Console.
  3. Turn on Enable Auto Update. Turn on Enable Auto Code Suggestion only if the workflow should be allowed to create a fix pull request.

The Action assesses repository security from a GitHub workflow, making it suitable for routine checks of a selected branch or recurring scans. Its outputs appear in three places: the Actions summary for the run, individual code-scanning alerts for findings, and the detailed project report in the Pervaziv Console.

When Auto Code Suggestion is enabled and the required permissions are present, the workflow can create a fix pull request. That separate change provides a review point for proposed remediation. Re-running analysis after changes provides results for the updated code.

Create .github/workflows/pervaziv-ai-action.yml:

name: Pervaziv AI Code Review
on:
push:
branches: [main]
schedule:
- cron: '0 6 * * 1'
jobs:
scan:
runs-on: ubuntu-latest
permissions:
security-events: write
actions: read
contents: write
pull-requests: write
steps:
- uses: pervaziv/pervaziv-ai-code-review@main
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
console-url: https://console.pervaziv.com

If Auto Code Suggestion is disabled, set contents: read and remove pull-requests: write. Customize the push branches and cron schedule to match the repository’s release policy.

For automated fix pull requests, GitHub repository settings must allow read and write workflow permissions and allow Actions to create pull requests.

Available project controls are:

  • Enable Auto Update
  • Enable Auto Code Suggestion
  • Enable AI Scan
  • AI Code Review: Allowed branches

The run summary includes the repository, branch, trigger, total findings and a link to the Console report. Code-scanning alerts include severity, file and line, rule details, CWE or OWASP tags when available, and the Console link.

Use the summary to locate the assessment, the alerts to investigate individual issues, and the Console report for broader project detail. Job completion and the presence or absence of findings describe different aspects of the run.

Choose a push trigger when the team needs a refreshed assessment as a branch changes. Use a schedule when the project needs recurring review independent of an individual pull request. The Action assesses the selected repository rather than only the files in a proposed change.

Keep the scan revision and trigger alongside the findings when comparing runs. A later run can have different dependency information, source context or coverage. Use GitHub alerts to investigate a specific issue and the Console report to understand the broader project assessment.

Auto Code Suggestion can create a pull request containing AI-generated fixes. This adds a reviewable proposed change, not an automatic merge. Turn the setting on only when the repository permits that workflow and grant only the permissions needed for it.

Review the diff, validate the affected behavior and re-assess the updated revision. If the goal is only to publish security findings, leave fix creation disabled and use the reduced job permissions described above.

The public Marketplace listing identifies aicodereview-v2.1 as the published release and notes that the Action is third-party and not certified by GitHub. It contains the current release and setup instructions.