> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/github-action-setup-for-local-code-scanning.md).

# ローカルオンプレミスコードスキャン用の GitHub Action セットアップ

## はじめに

Aikido Security Local Scanner を使用すると、GitHub Action 内で直接スキャンを実行でき、さらに **GitHub Enterprise Server (GHES)** 環境で使用できます。コードが外部に出ることはありません。スキャンはローカルで実行され、結果のみが Aikido Security プラットフォームにアップロードされます。この仕組みにより、最大限のプライバシーを確保しつつ、Aikido ダッシュボードで脆弱性を管理できます。

{% hint style="danger" %}
これは **該当しません** 通常のクラウドベースのスキャナーには適用されません。この GitHub Action のセットアップは、ローカルバイナリを使ったオンプレミススキャン専用です。
{% endhint %}

### 前提条件 <a href="#how-to-set-up-local-scanning" id="how-to-set-up-local-scanning"></a>

* GitHub Enterprise Server 環境（self-hosted または enterprise-managed）。
* CI/CD ランナー - GitHub Actions
* Aikido Local Scanning アカウント。
* システム要件:
  * CPU コア 2～4 個
  * RAM 8～16 GB
  * アウトバウンド HTTPS (443) アクセスが有効

### Local On-Prem Scanning の設定方法 <a href="#how-to-set-up-local-scanning" id="how-to-set-up-local-scanning"></a>

**前提条件**: ローカルスキャンが許可されたアカウントを作成済みであることを確認してください。 [ローカルスキャン用アカウントの作成に関する詳細情報](https://help.aikido.dev/en/articles/9070345-how-to-create-an-account-for-local-scanning-on-aikido).

#### 1. 認証トークンを生成する <a href="#id-1-get-your-authentication-token" id="id-1-get-your-authentication-token"></a>

1. 次の [Local Scanner 設定ページ](https://app.aikido.dev/settings/integrations/localscan).
2. 認証トークンを生成してコピーします。 **注** このトークンは 1 回しか表示できないことに注意してください。
3. このトークンを引数として追加する `--apikey` を、プロジェクトで Local Scanner を実行する際に使用します。
4. Settings > Secrets and variables > Actions に移動して、このトークンを GitHub Secrets に保存してください。

   ![保存された AIKIDO\_API\_KEY シークレットを表示しているリポジトリのシークレット管理画面。](/files/149223057ff954504e18d1fb8e38cfa1f849c87e)

#### 2. ローカルスキャナーの実行 <a href="#id-2-running-the-local-scanner" id="id-2-running-the-local-scanner"></a>

これで、リポジトリでスキャナーを実行するだけです。\
\
ローカルスキャナーはデフォルトブランチでのみ起動されるようにしてください。既定では、Aikido は依存関係およびコードの問題について、リポジトリ内の 1 つのブランチ（通常は main または master ブランチ）しかスキャンできません。そのため、Aikido プラットフォーム上でスキャン結果が混在しないよう、ローカルスキャナーはそのブランチでのみ実行することを推奨します。これはワークフローファイルの 'on' セクションで指定できます。

#### Docker を使用する <a href="#using-docker" id="using-docker"></a>

GitHub Actions でローカルスキャナーを使用する最も簡単な方法は、Docker イメージを使用することです。\
\
例 `.github/workflows/aikido-scan.yml`:

```yaml
on:
  push:
    branches:
      - main

name: Aikido Scan
jobs:
  aikido-local-scan-repo:
    runs-on: ubuntu-latest
    container:
      image: aikidosecurity/local-scanner:latest
    steps: 
      - uses: actions/checkout@v4 
        with: 
          token: ${{ secrets.GITHUB_TOKEN }} 
          path: my-repo 
      - name: スキャンを実行
        run: aikido-local-scanner scan my-repo --apikey ${{ secrets.AIKIDO_API_KEY }} --repositoryname MyRepo --branchname main
```

次の `--branchname` オプションをコマンド実行時に使用します。

これがこのリポジトリの最初のスキャンである場合、Aikido は指定した名前のリポジトリを作成し、すべてのスキャン結果を含めます。以後のスキャン結果は、Aikido 内でこのリポジトリ名の下に収集されます。

既定ではすべてのスキャン種別が実行されます。選択したスキャンのみ（例: SAST スキャンのみ）を実行したい場合は、 `--scan-types` オプション。CLI オプションの詳細は [こちら](https://help.aikido.dev/en/articles/9027526-local-scanner-cli-options).

を指定して、リリースまたは PR ゲーティング モードでスキャナーを実行することもできます。リリースゲーティング モードは、リリース前にリポジトリをスキャンする際に役立ちます。これにより、潜在的なリリース前に未解決の問題がないことを確認できます。リリースゲーティング モードで実行すると、スキャン完了後に選択した重大度以上の未解決の問題がある場合、スキャナープロセスは失敗します。PR ゲーティング モードは、PR 内で新たに導入された可能性のある問題をスキャンするために使用できます。

release または PR gating モードの詳細は [こちらの記事](/docs/docs-ja/kdosukyan/local-code-scanning/pr-gating-for-code-using-local-scanner.md).

#### 3. スキャン結果を確認する <a href="#id-3-check-your-scanning-results" id="id-3-check-your-scanning-results"></a>

最初のスキャン後:

* Aikido に、 `-repositoryname`.
* で指定した名前のリポジトリが表示されます。
* スキャンは次のモードで実行するよう設定できます。 **リリースゲーティング** または **PRゲーティング** 未解決の問題がある場合にデプロイをブロックしたいときに使用できます。

### 注意事項と制限

* Local Scanner アカウント **AutoFix は含まれません** UI 上では。AutoFix は次を通じて利用できます: [IDE 連携](/docs/docs-ja/ai-totsru/ide-plugins-overview.md)
* 既定では、すべてのスキャン種別が有効です。スキャンを制限するには（例: SAST のみ）、 `-scan-types` フラグを使用できます。
  * 「[Local Scanner の CLI オプション](/docs/docs-ja/kdosukyan/local-code-scanning/cli-options-for-local-scanner.md)」を読んで、ローカルスキャナー実行時に渡せるすべてのオプションを確認してください。
* 1 つのブランチのみ（通常は `main` または `master`）のみをスキャンし、結果が混在しないようにしてください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/github-action-setup-for-local-code-scanning.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
