Monarch Shield GitHub Action
Run the repository-bound scanner on pull requests:
name: payment-code-preflight
on:
pull_request:
permissions:
contents: read
jobs:
monarch-shield:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
- uses: ghostmonarch/x402ms@v0.2.0
with:
strict: "true"
For higher supply-chain assurance, replace v0.2.0 with the full release commit SHA. Do not use @main for a release gate.
What it runs
The Action executes the scanner bundled at the selected repository tag or SHA:
node "$GITHUB_ACTION_PATH/packages/x402/src/cli.js" doctor --root . --ci --strict
It does not download a caller-selected npm package. This keeps the Action implementation bound to the version you reviewed.
SARIF
- uses: ghostmonarch/x402ms@v0.2.0
continue-on-error: true
with:
strict: "true"
sarif: "true"
sarif-output: monarch-shield.sarif
- uses: github/codeql-action/upload-sarif@a2983b8bed1923f44751c5c43237f479442827b3 # v3
if: always()
with:
sarif_file: monarch-shield.sarif
SARIF transports the same static findings into code scanning. It does not add runtime enforcement or independent verification.
Boundary
Doctor is import-aware, single-file analysis for selected x402 v2 buyer patterns. A passing Action does not prove policy quality, authorization, runtime behavior, delivery, settlement, or production readiness.