Pin the version
Rename these inputs
GitHub ignores unknown inputs with only a warning, so the old names stop working without failing the run.Name a target
In v1.0 the agent could work out how to reach your app from the repository. v1.1.0 needs a target, and stops before verifying anything when it has none. Set one of:app_start_commandandapp_portfor an app that runs on the runner, usually withapp_install_commandandapp_build_commandapp_urlfor an app that is already deployed at a public URL
Choose where it runs
The newverification_mode input picks where the verification runs, and defaults to auto:
- A public repository runs on IronBee.
- A private repository with an Anthropic credential runs on your runner, as in v1.0.
- A private repository without one runs on IronBee, which needs the IronBee GitHub App on the repository.
verification_mode: local. See Platform and local verification.
An Anthropic credential is now optional. It’s needed only on your runner, or to fix findings.
What the action now does for you
- It commits the fixes. The agent only edits files. The action commits and pushes them: to the pull request branch on a pull request, otherwise to a new
ironbee/fix-<sha7>-<run_id>branch with a pull request. A fix whose re-verification fails is not pushed. - It passes or fails the job. The last step fails the job when the verification fails or ends without a verdict. If other jobs depend on this one, they now see that result.
- It writes the job summary. The report goes to the pull request comment and to the workflow run’s summary.
Changed defaults and outputs
ironbee_exclude_filesnow defaults totrue. IronBee’s generated files (.ironbee/,.claude/,.mcp.json,.gitignore) stay out of the commits the action makes.ironbee_collector_urlandironbee_console_urlare empty by default and derived by the CLI.- The
verdictoutput can bepass,fail,not_applicableorunknown. - New outputs:
mode,job_idandjob_url.artifacts_urlis set only when the verification ran on your runner. - Every
true/falseinput also accepts1/0,yes/noandon/off. Any other value fails the run and names the input.
Before and after
Next steps
Configuration
Every input and output in v1.1.0.
How it works
What happens in a run, from the plan to the report.