BACO outputs SARIF 2.1 format (report.sarif), which GitHub Code Scanning, Azure DevOps, and other CI tools can ingest to display findings as PR annotations and security alerts.
Add this workflow to .github/workflows/baco-scan.yml:
name: BACO Security Scan
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
jobs:
baco-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
- name: Build BACO
run: cargo build --release
- name: Install Semgrep
run: pip install semgrep
- name: Run BACO Scan
env:
MISTRAL_API_KEY: ${{ secrets.MISTRAL_API_KEY }}
run: ./target/release/baco scan --config baco.toml
- name: Upload SARIF to GitHub Code Scanning
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: baco-output/report.sarifRequired: Set MISTRAL_API_KEY (or your LLM provider key) as a GitHub repository secret.
Create a baco.toml config file in your repository root. See Configuration Reference for all options.
For faster CI runs, disable heavy LLM phases:
[scanner.performance]
enable_threat_modeling = false
enable_root_cause_dedup = false
enable_cve_bootstrap = false
enable_variant_search = falseAfter the workflow runs:
- Code Scanning alerts: Navigate to GitHub → Security → Code Scanning alerts
- PR annotations: Findings automatically appear as inline annotations on changed lines in pull requests
For pull request reviews, limit the scan to only files changed in the PR using --diff:
baco scan --config baco.toml --diff origin/main...HEADThe --diff <revspec> flag filters findings to include only those in files modified in the specified git revision range. Use this for:
- PR reviews: scan only changed files (
origin/main...HEAD) - Incremental checks: compare against a specific commit (
main..feature-branch) - Reducing noise: focus on recent changes rather than the entire codebase
The revspec follows standard git syntax (e.g., A...B for changes in B not in A, A..B for changes reachable from B but not A).
Use the SARIF results tab extension to upload report.sarif as a pipeline artifact.
Add report.sarif as a SARIF report artifact:
baco-scan:
script:
- cargo build --release
- ./target/release/baco scan --config baco.toml
artifacts:
reports:
sast: baco-output/report.sarifAny tool that reads SARIF 2.1 can ingest report.sarif:
- CodeQL CLI
- Semgrep CLI
- Microsoft SARIF Viewer
- Custom parsers and dashboards