> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/github-action-setup-for-local-code-scanning.md).

# ローカルオンプレミスコードスキャン用のGitHub Actions設定

## はじめに

Aikido Security Local Scanner を使用すると、GitHub Action 内で直接スキャンを実行でき、さらにあなたが **GitHub Enterprise Server (GHES)** の環境を使用している場合にも対応します。コードが外部に出ることはありません。スキャンはローカルで実行され、結果のみが Aikido Security プラットフォームにアップロードされます。この構成により、Aikido ダッシュボードで脆弱性を管理しながら、最大限のプライバシーを確保できます。

{% hint style="danger" %}
これは **対象外** です。通常のクラウドベースのスキャナーには適用されません。この GitHub Action のセットアップは、ローカルバイナリを使用したオンプレミススキャン専用です。
{% endhint %}

### 前提条件 <a href="#how-to-set-up-local-scanning" id="how-to-set-up-local-scanning"></a>

* GitHub Enterprise Server の環境（セルフホストまたは企業管理）です。
* CI/CD ランナー - GitHub Actions
* Aikido Local Scanning アカウント。
* システム要件：
  * CPU コア 2～4 個
  * RAM 8～16 GB
  * Outbound HTTPS（443）アクセスが有効

### ローカルオンプレミススキャンの設定方法 <a href="#how-to-set-up-local-scanning" id="how-to-set-up-local-scanning"></a>

**前提条件**：Local Scanning を利用できるアカウントが作成済みであることを確認してください。 [Local Scanning アカウントの作成に関する詳細情報](https://help.aikido.dev/en/articles/9070345-how-to-create-an-account-for-local-scanning-on-aikido).

#### 1. 認証トークンを生成する <a href="#id-1-get-your-authentication-token" id="id-1-get-your-authentication-token"></a>

1. へ移動してください [Local Scanner の設定ページ](https://app.aikido.dev/settings/integrations/localscan).
2. 認証トークンを生成してコピーします。 **注** このトークンを確認できるのは 1 回だけです。
3. このトークンを引数として追加します `--apikey` を、プロジェクトで Local Scanner を実行する際に使用します。
4. Settings > Secrets and variables > Actions に移動し、このトークンを GitHub Secrets に保存します。

   ![保存されている AIKIDO\_API\_KEY シークレットを表示しているリポジトリのシークレット管理インターフェース。](/files/149223057ff954504e18d1fb8e38cfa1f849c87e)

#### 2. ローカルスキャナーを実行する <a href="#id-2-running-the-local-scanner" id="id-2-running-the-local-scanner"></a>

あとは、リポジトリでスキャナーを実行するだけです。\
\
ローカルスキャナーは必ずデフォルトブランチでのみ起動するようにしてください。Aikido ではデフォルトで、リポジトリ内の 1 つのブランチに対して依存関係とコードの問題をスキャンできます。通常は main または master ブランチです。そのため、Aikido プラットフォーム上でスキャン結果が混在しないよう、ローカルスキャナーはそのブランチでのみ実行することを推奨します。これはワークフローファイルの 'on' セクションで指定できます。

#### Docker を使用する <a href="#using-docker" id="using-docker"></a>

GitHub Actions でローカルスキャナーを使う最も簡単な方法は、Docker イメージを使用することです。\
\
例 `.github/workflows/aikido-scan.yml`:

```yaml
on:
  push:
    branches:
      - main

name: Aikido Scan
jobs:
  aikido-local-scan-repo:
    runs-on: ubuntu-latest
    container:
      image: aikidosecurity/local-scanner:latest
    steps: 
      - uses: actions/checkout@v4 
        with: 
          token: ${{ secrets.GITHUB_TOKEN }} 
          path: my-repo 
      - name: Run scan
        run: aikido-local-scanner scan my-repo --apikey ${{ secrets.AIKIDO_API_KEY }} --repositoryname MyRepo --branchname main
```

次を使って希望するブランチを指定します： `--branchname` を、コマンド実行時に指定します。

このリポジトリに対する最初のスキャンである場合、Aikido は指定した名前のリポジトリを作成し、すべてのスキャン結果をそこに保存します。以降のスキャン結果は、Aikido ではこのリポジトリ名の下に集約されます。

デフォルトではすべてのスキャンタイプが実行されます。選択したスキャンのみ（例：SAST スキャンのみ）を実行したい場合は、 `--scan-types` オプションです。CLI オプションの詳細は以下で確認できます。 [こちら](https://help.aikido.dev/en/articles/9027526-local-scanner-cli-options).

を指定することで可能です。リリースまたは PR ゲーティングモードでスキャナーを実行することもできます。リリースゲーティングモードは、リリース前にリポジトリをスキャンする際に役立ち、潜在的なリリース前に未解決の問題がないことを নিশ্চিতします。リリースゲーティングモードで実行すると、スキャン完了後に選択した重大度以上の未解決の問題がある場合、スキャナーの処理は失敗します。PR ゲーティングモードは、PR 内で新たに導入された可能性のある問題をスキャンするために使用できます。

リリースまたは PR ゲーティングモードの詳細は、 [この記事](/docs/docs-ja/kdosukyan/local-code-scanning/pr-gating-for-code-using-local-scanner.md).

#### 3. スキャン結果を確認する <a href="#id-3-check-your-scanning-results" id="id-3-check-your-scanning-results"></a>

最初のスキャン後：

* Aikido に、 `-repositoryname`.
* で指定した名前のリポジトリが表示されます。その後のスキャンでは、同じリポジトリが新しい検出結果で更新されます。
* スキャンを **release gating** または **PR gating** モードで実行するように設定すれば、未解決の問題があるデプロイをブロックできます。

### 注意事項と制限

* Local Scanner アカウント **には AutoFix は含まれません** 。AutoFix は [IDE 連携](/docs/docs-ja/ai-tsru/ide-plugins-overview.md)
* で利用できます。デフォルトでは、すべてのスキャンタイプが有効です。 `-scan-types` フラグを使用して、スキャンを制限できます（例：SAST のみ）。
  * 「[CLI option for Local Scanner](/docs/docs-ja/kdosukyan/local-code-scanning/cli-options-for-local-scanner.md)」を読んで、ローカルスキャナー実行時に渡せるすべてのオプションを確認してください。
* 混在を避けるため、スキャンするブランチは 1 つだけ（通常は `main` または `master`）にしてください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/github-action-setup-for-local-code-scanning.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
