CI/CD Integration¶
ppee-cli works well as a pipeline step. It needs no GUI and no network, starts in milliseconds, exits non-zero on failure, and writes machine-readable JSON. Typical uses:
| Goal | How |
|---|---|
| Release gate: ship only signed, hardened binaries | ppee-policy.sh with --require-signature --require-hardening |
| Supply-chain check: detect tampering after signing | Embedded digest vs Authentihash (details) |
| Regression check: catch new imports or lost flags | Diff --json --imports --headers against the previous release |
| Malware triage pipeline: hash, extract IOCs, cluster | --hashes --strings --imports, or the similarity DB |
| Artifact metadata: attach a report to every build | --json --all --no-similarity > report.json |
flowchart LR
B[Build] --> A[Windows artifacts<br/>.exe .dll .sys]
A --> P[ppee-cli --json]
P --> G{Policy gate}
G -- pass --> S[Sign / publish]
G -- fail --> X[Fail pipeline<br/>+ report artifact] Getting ppee-cli into the pipeline¶
Build once and push to your registry (Docker guide). Then either run the image as the job container, or call it with docker run. Its entry point is ppee-cli, so for shell steps use docker run from the runner:
Cache or download the release ppee-cli and put it on PATH. The runner needs x86-64 Linux with glibc 2.38+ (for example ubuntu-24.04); it does not run on musl (Alpine).
Use ppee-cli.exe directly. It's the only option that also reports WinVerifyTrust validity (chain trust and revocation).
Rules of thumb¶
- Always pass
--no-similarityin CI so no database is written and nothing is remembered between jobs. - Pass
--no-update-checkon Windows runners. The Docker image already does. - Select only the sections you need.
--stringsand--resourcesare the slow, large ones. - Keep the JSON as a build artifact; it's a precise record of what shipped.
Pages¶
- GitHub Actions
- GitLab CI
- Jenkins & Azure Pipelines
- Policy gates: the reusable
ppee-policy.shscript and individual jq checks