deidproof as a CI gate: how are you wiring it into your release pipeline? #7
cognis-digital
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
deidproofis built to run in CI:deidproof check export.csv --qi ... --sensitive ... -k 5 -l 2exits0on pass,2on a privacy failure, and1on misuse, and it can emit SARIF 2.1.0 for GitHub code scanning.How are people wiring it into their release pipeline?
2?One sharp edge worth flagging for CI users: if you pass
-kbut forget--quasi-identifiers, older builds computed no k at all and the check silently passed. The current code treats that as a usage error (exit 1) so a typo can never turn into a false "de-identified" green check. If you scriptdeidproof, prefer being explicit about both--qiand--sensitive, and gate your job on the exit code, not on grepping the text output.What does your gate look like? Share your workflow YAML.
All reactions