> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/github-action-setup-for-local-code-scanning.md).

# ローカルオンプレミスコードスキャンのためのGitHub Actionセットアップ

## はじめに

Aikido Security ローカルスキャナーを使用すると、GitHub Action 内で直接スキャンを実行できます。または、 **GitHub Enterprise Server (GHES)** 環境を使用している場合にも実行できます。コードが外部に出ることはありません。スキャンはローカルで実行され、結果のみが Aikido Security プラットフォームにアップロードされます。この構成により、Aikido ダッシュボードで脆弱性を管理しながら、最大限のプライバシーを確保できます。

{% hint style="danger" %}
これは **該当しません** 通常のクラウドベースのスキャナーには。これは、ローカルバイナリを使用したオンプレミススキャン専用の GitHub Action セットアップです。
{% endhint %}

### 前提条件 <a href="#how-to-set-up-local-scanning" id="how-to-set-up-local-scanning"></a>

* GitHub Enterprise Server 環境（セルフホストまたは企業管理）です。
* CI/CD ランナー - GitHub Actions
* Aikido ローカルスキャンのアカウント。
* システム要件:
  * CPU コア 2〜4 個
  * RAM 8〜16 GB
  * アウトバウンド HTTPS (443) アクセスが有効

### ローカルオンプレミススキャンのセットアップ方法 <a href="#how-to-set-up-local-scanning" id="how-to-set-up-local-scanning"></a>

**前提条件**: ローカルスキャンを利用できるアカウントを作成しておいてください。 [ローカルスキャン用アカウントの作成に関する詳細](https://help.aikido.dev/en/articles/9070345-how-to-create-an-account-for-local-scanning-on-aikido).

#### 1. 認証トークンを生成する <a href="#id-1-get-your-authentication-token" id="id-1-get-your-authentication-token"></a>

1. 次へ移動 [Local Scanner 設定ページ](https://app.aikido.dev/settings/integrations/localscan).
2. 認証トークンを生成してコピーします。 **注記** このトークンは一度しか表示できません。
3. このトークンを引数として追加します `--apikey` プロジェクトで Local Scanner を実行するときに。
4. Settings > Secrets and variables > Actions に移動して、このトークンを GitHub Secrets に保存します。

   ![保存された AIKIDO\_API\_KEY シークレットを表示するリポジトリのシークレット管理画面。](/files/149223057ff954504e18d1fb8e38cfa1f849c87e)

#### 2. ローカルスキャナーの実行 <a href="#id-2-running-the-local-scanner" id="id-2-running-the-local-scanner"></a>

あとは、リポジトリでスキャナーを実行するだけです。\
​\
ローカルスキャナーは必ずデフォルトブランチでのみトリガーされるようにしてください。Aikido では、依存関係とコードの問題について、リポジトリ内の 1 つのブランチ（通常は main または master ブランチ）をスキャンすることがデフォルトでサポートされています。そのため、Aikido プラットフォーム上でスキャン結果が混在しないよう、ローカルスキャナーはそのブランチでのみ実行することを推奨します。これはワークフローファイルの 'on' セクションで指定できます。

#### Docker を使用する <a href="#using-docker" id="using-docker"></a>

GitHub Actions でローカルスキャナーを使用する最も簡単な方法は、Docker イメージを使用することです。\
​\
例 `.github/workflows/aikido-scan.yml`:

```yaml
​on:
  push:
    branches:
      - main

name: Aikido スキャン
jobs:
  aikido-local-scan-repo:
    runs-on: ubuntu-latest
    container:
      image: aikidosecurity/local-scanner:latest
    steps: 
      - uses: actions/checkout@v4 
        with: 
          token: ${{ secrets.GITHUB_TOKEN }} 
          path: my-repo 
      - name: スキャンを実行
        run: aikido-local-scanner scan my-repo --apikey ${{ secrets.AIKIDO_API_KEY }} --repositoryname MyRepo --branchname main
```

次の `--branchname` オプションを使用してコマンドを実行します。

これがこのリポジトリの最初のスキャンである場合、Aikido は指定した名前のリポジトリを作成し、すべてのスキャン結果を含めます。以後のスキャン結果は、Aikido 内でこのリポジトリ名の下に集約されます。

デフォルトではすべてのスキャンタイプが実行されます。スキャンの一部のみ（例: SAST スキャンのみ）を実行したい場合は、 `--scan-types` オプションです。CLIオプションの詳細はこちらで確認できます [こちら](https://help.aikido.dev/en/articles/9027526-local-scanner-cli-options).

を指定してスキャンタイプを渡すことで実行できます。また、スキャナーをリリースゲーティングモードまたは PR ゲーティングモードで実行することもできます。リリースゲーティングモードは、公開前にリポジトリをスキャンする際に役立ち、リリース候補に開いている問題がないことを保証します。リリースゲーティングモードで実行すると、スキャン完了後に選択した重大度以上の未解決の問題がある場合、スキャナー処理は失敗します。PR ゲーティングモードは、PR に新たに導入された可能性のある問題をスキャンするために使用できます。

リリースゲーティングモードまたは PR ゲーティングモードの詳細は、 [この記事](/docs/docs-ja/kdosukyan/local-code-scanning/pr-gating-for-code-using-local-scanner.md).

#### 3. スキャン結果を確認する <a href="#id-3-check-your-scanning-results" id="id-3-check-your-scanning-results"></a>

最初のスキャン後:

* 指定した `-repositoryname`.
* という名前で Aikido にリポジトリが表示されます。その後のスキャンでは、新しい検出結果で同じリポジトリが更新されます。
* スキャンを **リリースゲーティング** または **PR ゲーティング** モードで実行するよう設定すると、未解決の問題があるデプロイをブロックできます。

### 注意事項と制限

* ローカルスキャナーのアカウント **には AutoFix は含まれません** UI 上では。AutoFix は [IDE 統合](/docs/docs-ja/ai-totsru/ide-plugins-overview.md)
* デフォルトでは、すべてのスキャンタイプが有効です。 `-scan-types` フラグを使って、スキャンを制限できます（例: SAST のみ）。
  * 「[ローカルスキャナー用の CLI オプション](/docs/docs-ja/kdosukyan/local-code-scanning/cli-options-for-local-scanner.md)」を読んで、ローカルスキャナー実行時に渡せるすべてのオプションを確認してください。
* 1 つのブランチ（通常は `main` または `master`）のみをスキャンして、結果が混在しないようにしてください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/github-action-setup-for-local-code-scanning.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
