Monarch
UseRaw agent sources are listed in /docs/manifest.json

Monarch Shield GitHub Action

Run the repository-bound scanner on pull requests:


name: payment-code-preflight



on:

  pull_request:



permissions:

  contents: read



jobs:

  monarch-shield:

    runs-on: ubuntu-latest

    steps:

      - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6

      - uses: ghostmonarch/x402ms@v0.2.0

        with:

          strict: "true"

For higher supply-chain assurance, replace v0.2.0 with the full release commit SHA. Do not use @main for a release gate.

What it runs

The Action executes the scanner bundled at the selected repository tag or SHA:


node "$GITHUB_ACTION_PATH/packages/x402/src/cli.js" doctor --root . --ci --strict

It does not download a caller-selected npm package. This keeps the Action implementation bound to the version you reviewed.

SARIF


- uses: ghostmonarch/x402ms@v0.2.0

  continue-on-error: true

  with:

    strict: "true"

    sarif: "true"

    sarif-output: monarch-shield.sarif



- uses: github/codeql-action/upload-sarif@a2983b8bed1923f44751c5c43237f479442827b3 # v3

  if: always()

  with:

    sarif_file: monarch-shield.sarif

SARIF transports the same static findings into code scanning. It does not add runtime enforcement or independent verification.

Boundary

Doctor is import-aware, single-file analysis for selected x402 v2 buyer patterns. A passing Action does not prove policy quality, authorization, runtime behavior, delivery, settlement, or production readiness.