CircleCI
Add the certified orb, call the scan job with your frameworks, and gate builds on compliance findings. Offline, no API key, and your code never leaves the executor.
3 steps.
CircleCI runs the scanner image directly as the job's executor, there is nothing to install.
version: 2.1
jobs:
scrutora-scan:
docker:
- image: ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461
steps:
- checkout
- run:
name: Scrutora compliance scan
command: |
scan . --no-ai \
--frameworks dpdpa,hipaa \
--fail-on high \
--sarif-output /tmp/scrutora.sarif
- store_artifacts:
path: /tmp/scrutora.sarif
workflows:
compliance:
jobs:
- scrutora-scanThe job scans offline and stores the SARIF report as a build artifact. fail-on fails the job when a finding at or above your chosen severity is present.
By default nothing leaves your runner, which is why the scan above needs no account and no key. Add --upload and the scan posts its RESULTS to your Scrutora account when it finishes: the findings, the data map, the RoPA entries and the dependency inventory travel, your source never does. Paid plans only; the scan itself stays free forever. Store the key as a secret (GitHub: Actions secret, GitLab: masked CI variable, Bitbucket: repository variable, CircleCI: context, Azure: pipeline secret, Cloud Build: Secret Manager) and expose it as SCRUTORA_API_KEY so it never reaches your build log. Repository, commit, branch and PR number are read from the CI environment, and the scan is filed under a project named after the repository unless you pass --project. Re-running the same commit returns the scan already stored rather than adding a second one, so a retried pipeline does not distort the trend line. If the upload fails, the build result is unchanged: the scan already gave its verdict, and the step logs a warning rather than failing the job. On GitHub Actions you can set upload: true on the action itself instead of running the container by hand, and read the resulting scan id from the scan-id output.
docker run --rm -v "$PWD:/src" -w /src \
-e SCRUTORA_API_KEY \
ghcr.io/nirvahana/dpdp-scan@sha256:71e306bdab91587e01ed6b83a1d2c3baecf4c55ecf880b440a5ab76fe85eb461 \
scan . --no-ai \
--frameworks dpdpa,hipaa \
--json-output scrutora.json \
--output scrutora-report.pdf \
--upload
# SCRUTORA_API_KEY is read from the environment, never passed on the command
# line, so it stays out of your build log. Add --project "my-service" to file
# the scan somewhere other than a project named after the repository.
# ── GitHub Actions: use the action's own inputs instead ─────────────────────
# - id: scan
# uses: scrutora/scrutora-scan@v1
# with:
# upload: true
# api-key: ${{ secrets.SCRUTORA_API_KEY }}
# - run: echo "Synced as ${{ steps.scan.outputs.scan-id }}"After the first run.
fail-on fails the job on high/critical findings, or run report-only.
The report is stored as a CircleCI artifact for download and review.
Every finding cites the exact obligation, not a generic rule id.
It's a standard orb, with nothing to install on your executors.