> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/pr-gating/jenkins-pr-gating-using-local-scanner.md).

# ローカルスキャナーを使ったJenkinsのPRゲーティング

Aikido Local Scanner は、CI パイプラインでセキュリティゲートを強制するために使用できます。

{% hint style="info" %}
クラウド接続されたワークスペース（GitHub、BitBucket など）でも PR ゲーティングを使用できます。CI をご覧ください [統合セクション](https://help.aikido.dev/section/ci-integrations/sg3q6UrIf4qE).
{% endhint %}

PR ゲーティングにより、新しいコードがデフォルトブランチにマージされる前にセキュリティ基準を満たしていることを確認できます。プルリクエストで導入された変更のみをスキャンします。スキャンで、設定した重大度しきい値以上の新しい問題が検出された場合、CI パイプラインは失敗します。

これにより、新しい脆弱性の混入を防ぎつつ、既存の検出結果は別途対応できます。

{% hint style="info" %}
また、次もサポートしています [リリースゲーティング](/docs/docs-ja/kontenaimjisukyan/local-image-scanning/release-gating-for-container-images-using-local-image-scanner.md) リリース時にチェックを強制したいチーム向けです。
{% endhint %}

PR ゲーティングを有効にするには、次を追加します `--fail-on <severity>` オプションで、希望する重大度レベルを選択します。次に、次を追加します `--gating-mode pr` オプションを追加して、PR ゲーティングを実行することを示します。また、ベース（`--base-commit-id <commit-id>`）とヘッドコミット（`--head-commit-id <commit-id>`）を指定する必要があります。ベースコミット ID に対して以前にスキャンが実行されている場合、スキャン結果はその結果と比較されます。そうでない場合は、デフォルトブランチで最も最近のスキャン結果と比較されます。

Jenkins 環境での Local Scanner のセットアップに関する一般情報は、次をご覧ください [この記事](/docs/docs-ja/kdosukyan/local-code-scanning/github-action-setup-for-local-code-scanning.md).

#### 仕組み

必要な要素は 3 つあります:

1. **SCM と Jenkins の統合。**
2. **Multibranch Pipeline ジョブ** を使用して *プルリクエストを検出* 動作。これにより、Jenkins は開いている各プルリクエストをビルドします。PR ビルドでは、Jenkins はソースブランチをチェックアウトし、標準の変更要求環境変数（`CHANGE_ID`, `CHANGE_TARGET`, `CHANGE_BRANCH`).
3. **Aikido Local Scanner**、あなたの `Jenkinsfile` で `--gating-mode pr`.

```
PR が開かれる/更新される  ──►  SCM が webhook を送信  ──►  Jenkins Multibranch PR ビルド
                                                      │
                                                      ▼
                                        aikido-local-scanner --gating-mode pr
                                                      │
                                  新しい問題 ≥ --fail-on？  ── はい ──► ビルドは失敗
                                                      │                    │
                                                      いいえ                   ▼
                                                      ▼            ビルドステータス = FAILED
                                                ビルドは成功               │
                                                      │                    ▼
                                                      ▼          SCM がマージをブロック
                                              SCM のチェックに合格
```

#### Multibranch Pipeline の設定

プルリクエストのビルドには **Multibranch Pipeline** ジョブが必要です。

1. Jenkins で次を選択します **New Item → Multibranch Pipeline**、名前を付けて、次を選択します **OK**.
2. 次の場所で **ブランチソース**、 **ソースを追加 → SCM を選択**.
3. 次を選択します **リポジトリ**.
4. 次の場所で **動作**、 **追加 → プルリクエストを検出** を追加し、無効にします **ブランチを検出。**
5. 次の場所で **Multibranch Pipeline トリガーのスキャン**、次を有効にします **webhook トリガー → プルリクエストの作成またはソースブランチの更新** オプションを選択してください。
6. 次のままにします **ビルド設定** を **Jenkinsfile による**、 **Script Path** = `Jenkinsfile`.
7. 次を選択します **保存**。Jenkins はリポジトリをスキャンし、開いている各プルリクエストのビルドを開始します。

#### Jenkinsfile に Aikido PR ゲーティングステージを追加

次を追加（または拡張）します `Jenkinsfile` をリポジトリのルートに配置します。以下のステージは **プルリクエストのビルドでのみ実行されます**、Git からベースコミットとヘッドコミットを取得し、PR ゲーティングモードでスキャナーを実行します。ゲートに失敗したときにスキャナーが非ゼロ終了することでビルドが失敗します。

```groovy
pipeline {
    agent any

    environment {
        // https://help.aikido.dev/code-scanning/local-code-scanning/jenkins-setup-for-local-code-scanning#id-1-get-your-authentication-token で設定された認証情報を取得します
        AIKIDO_API_KEY = credentials('aikido-local-scanner-api-key')
        AIKIDO_REPO_NAME = 'my-repo'
    }

    stages {
        stage('Aikido PR Gating') {
            // CHANGE_ID はプルリクエストのビルドでのみ設定されます
            when { expression { env.CHANGE_ID != null } }
            steps {
                script {
                    // 対象（宛先）ブランチがローカルで利用できることを確認します
                    sh "git fetch origin ${env.CHANGE_TARGET}"

                    // Head = PR ソースブランチの先端（マージされる内容）
                    def headCommit = sh(
                        script: 'git rev-parse HEAD',
                        returnStdout: true
                    ).trim()

                    // Base = 宛先ブランチの先端（マージ先）
                    def baseCommit = sh(
                        script: "git rev-parse origin/${env.CHANGE_TARGET}",
                        returnStdout: true
                    ).trim()

                    echo "PR #${env.CHANGE_ID}: ${env.CHANGE_BRANCH} -> ${env.CHANGE_TARGET}"
                    echo "ベースコミット: ${baseCommit}"
                    echo "ヘッドコミット: ${headCommit}"

                    // Docker 版。新しい問題が
                    // --fail-on 以上で検出されると、スキャナーは非ゼロで終了し、ビルドは失敗します。
                    sh """
                        docker run --rm \
                          -v "\$(pwd):/scan-target" \\
                          aikidosecurity/local-scanner \
                          scan /scan-target \
                          --apikey "\$AIKIDO_API_KEY" \\
                          --repositoryname "\$AIKIDO_REPO_NAME" \\
                          --branchname "${env.CHANGE_BRANCH}" \\
                          --gating-mode pr \\
                          --fail-on critical \\
                          --base-commit-id ${baseCommit} \\
                          --head-commit-id ${headCommit}
                    """
                }
            }
        }
    }
}
```

**スキャナーのバイナリがエージェントにインストールされている場合** Docker の代わりに、次の `docker run …` ブロックを次のものに置き換えます:

```groovy
sh """
    aikido-local-scanner scan ./ \\
      --apikey "\$AIKIDO_API_KEY" \\
      --repositoryname "\$AIKIDO_REPO_NAME" \\
      --branchname "${env.CHANGE_BRANCH}" \\
      --gating-mode pr \\
      --fail-on critical \\
      --base-commit-id ${baseCommit} \\
      --head-commit-id ${headCommit}
"""
```

* **`--fail-on critical`** 重大度しきい値を設定します。次のいずれかに変更すると `高`, `中`、または `低` より厳格にゲートできます。

必要に応じて、SCM でのゲート強制を設定してください。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kdosukyan/local-code-scanning/pr-gating/jenkins-pr-gating-using-local-scanner.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
