> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/application-security/get-started/connect-code-and-build-providers/ci-cd-runs/add-github-actions.md).

# GitHub Actions

Integrate Prisma Cloud with GitHub Actions to allow dynamic, automated, and context-specific scans within your development workflow. This includes continuous scanning of your workflow whenever changes are pushed or triggered, integrating security checks, and catching issues as soon as they are introduced. Additionally, it automates shift-left actions such as notifying developers or creating tickets, based on scan results.

1. Before you begin.
   1. [Generate and copy the Prisma Cloud access key](/content-collections/administration/create-access-keys.md) to enable access to Prisma Cloud. The access key includes a key ID and secret.
   2. Add the Prisma Cloud IP addresses and hostname for Application Security to an [allow list](/content-collections/get-started/console-prerequisites.md) to enable access to the Prisma Cloud Console.
   3. Grant the Prisma user integrating Prisma Cloud with GitHub Actions **Administrator** user permissions.
2. On the Prisma Cloud Application Security console.
   1. In Application Security, select **Home** > **Settings** > **Connect Provider** > **Code & Build Providers**.

      <figure><img src="/files/XKnsAzR4JSx7Q1BGkVMp" alt="connect provider menu"><figcaption></figcaption></figure>
   2. Select **GitHub Actions** (under CI/CD Runs) in the catalog that is displayed.

      <figure><img src="/files/LSFiWuVPnPC2pbtFdyTL" alt="connect provider"><figcaption></figcaption></figure>

      The **Add Environment Variable** step of the integration wizard is displayed.

      <figure><img src="/files/WPl8xwGPto5d04UhwtK3" alt="gha add envstep wizard"><figcaption></figcaption></figure>
3. Add the Prisma Cloud access key as an environment variable to **GitHub Secrets**.
   1. Copy the Prisma access key name from the **Name** field.
   2. Copy the access key ID and secret from the **Value** step
   3. Add the access key as an environment variable to GitHub Actions.

      For more information on passing secrets as environment variables to GitHub Actions, refer to <https://docs.github.com/actions/security-guides/encrypted-secrets>.
4. Click **Next**.

   The **Configure Job** step of the integration wizard is displayed.

   <figure><img src="/files/UyEvfXX1EFm4bB1g7IKV" alt="gha conf job step wizard"><figcaption></figcaption></figure>
5. Copy and paste the following code into your GitHub Actions job configuration.

   The `prisma-api-url` value is environment-specific. Therefore, replace the value with the appropriate value for your environment.

   ```
   steps:
         - name: Checkout repo
           uses: actions/checkout@v2

         - name: Run Prisma Cloud
           id: Prisma Cloud
           uses: bridgecrewio/checkov-action@master
           env:
             PRISMA_API_URL: https://api2.prismacloud.io
           with:
             api-key: ${{ secrets.BC_API_KEY }}
             use_enforcement_rules: true
   ```

   For more job configuration options, such as `use_enforcement_rules` and `framework`, refer to the [Checkov Action](https://github.com/bridgecrewio/checkov-action/blob/master/action.yml) yml file.
6. Select **Done**.
7. Verify integration: In **Application Security**, select **Home** > **Settings** > **CI/CD Runs** tab.

   Your integrated GitHub Actions repositories will be displayed. You may have to wait for up to three minutes before the status of the integration is updated.
8. Next step: Monitor and manage scan results.
   * The next GitHub Actions scan will automatically include the selected repositories
   * To view scan results and resolve issues, in **Application Security** select **Home** > **Projects**.

     Refer to [Monitor and Manage Code Build Issues](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/application-security/risk-management/monitor-and-manage-code-build/monitor-and-manage-code-build.md) for more information


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/application-security/get-started/connect-code-and-build-providers/ci-cd-runs/add-github-actions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
