Continuous integration

Action reference

Generated from the Action’s own manifest. Every input below is one the Action accepts today.

Inputs

InputDefaultDescription
contractsrequiredOne or more Soroban contract IDs (C…, 56 characters), separated by spaces or newlines.
threshold17280Act-now threshold in LEDGERS. An entry at or below it fails the job — the boundary is inclusive. Default 17,280 (~1 day at ~5 s/ledger). Both health tiers move with it.
keys-file—Path to a JSON file `{ "dataKeys": [...] }` listing the contract's persistent and temporary ledger keys. Exactly one contract when set. Without it (or no-data-keys) the scan can read only the instance and code entries.
no-data-keysfalse'true' to declare that the contract has no data keys beyond its instance. A caller declaration — only the contract's author can know it. Mutually exclusive with keys-file.
require-declared-scopetrue'true' (the default) fails the job when a contract's data-key scope was not declared via keys-file or no-data-keys. Leave it on for a contract you own: without it, a green build means only "the entries I could see are healthy" and says nothing about persistent storage.
versionlatestVersion of @evergreen-stellar/cli to run. Pin it for reproducible CI.

Read from action.yml at build time.

Output

OutputMeaning
exit-code0 healthy · 1 at or below threshold · 2 error · 3 scan incomplete

The step fails the job on a non-zero code, and the output is there so a later step can tell the codes apart — for instance to comment on the pull request differently for 1 and 3. Exit codes

What runs on the runner

Node 24 via actions/setup-node, then the published CLI via npx --yes. The Action reads no lockfile and installs nothing into your repository.

Package-manager caching is explicitly disabled, and that is not a preference. setup-node@v5 turns it on by default, detects the caller’s lockfile, and shells out to that package manager — so in a repository with a pnpm-lock.yaml and no pnpm on the runner it fails with Unable to locate executable file: pnpm before this Action has run a line of its own. Measured on 2026-09-25, when both demo jobs died there and the scan step was skipped; it looked like the publish had not worked.

Declaring scope in CI

keys-file and no-data-keys are mutually exclusive, and require-declared-scope turns the absence of both into a failure. On a contract you own that is the right setting: an undeclared scope in CI is a gap in the check, not a caveat on the result.

Next JSON shape ScanResult, shown from the declaration that defines it.