# Run `kix check --sarif` in CI

Use `kix check --sarif` when your CI system accepts SARIF 2.1.0 findings. The
command still runs cluster evaluation and the normal checks, but writes SARIF
instead of the terminal summary.

This guide assumes the job has Kix and the cluster's Nix dependencies
available.

## Write the SARIF file

Redirect stdout to a file:

<Command
  commands={["kix check 19-scorecards --sarif > kix-results.sarif"]}
  cwd="kix-examples/"
/>

Upload `kix-results.sarif` with your CI provider's SARIF or code-scanning
integration. Preserve the command's exit status so error-level checks still
fail the job, even if the upload step runs after a failure.

The captured example below contains warning and note findings from the
checked-in scorecard scenario:

<Command expandable {...sarif} />

Each result includes a rule ID, SARIF level, and message. Kix emits a valid
empty SARIF run when the cluster has no scorecard findings, so the upload step
can use the same path for clean and failing builds.

An error-severity finding becomes a failed assertion, so evaluation stops
before producing a scorecard report. Kix instead writes the evaluation failure
as a single error-level SARIF result. When the error message identifies the
rule, the result is attributed to that rule. Only one result appears because
evaluation stops at the first failed assertion.

Keep this behavior in mind before promoting a rule to `error` in
[Override scorecard severity](/docs/how-to/policy-ci-and-compliance/override-scorecard-severity/).
An error rule stops the build instead of contributing all of its findings to
the completed report.

## Check the file before upload

A short validation catches an empty or truncated shell redirect:

<Command
  commands={[
    "jq -e '.version == \"2.1.0\" and (.runs | length) > 0' kix-results.sarif",
  ]}
  cwd="kix-examples/"
/>

Run the upload step even when `kix check` exits non-zero, then propagate the
original failure. The exact job syntax depends on the CI provider.

:::note[Reference]
See [`kix check`](/docs/reference/cli/check/) for check phases and exit
behavior, and [Finding schema](/docs/reference/scorecard/finding-schema/) for
the underlying Kix finding fields.
:::