sphynx-sh in your project and commit the lockfile. Name suite files *.eval.ts so the action can find them.
Create an API key with evals:read and evals:write and save it as the SPHYNX_API_KEY repository secret. Use a dedicated organization for CI.
In that organization, connect the harness under Settings > Harnesses and make it the default, shared with everyone in the organization. API keys cannot use personal connections. Provider credentials stay in Sphynx, not in GitHub or the suite.
COMMIT_SHA with a reviewed action commit. The action runs the sphynx CLI you installed, with Node 20 or later. It does not install dependencies.
Each suite file starts one batch: one run per case per variant. The job summary links each batch as soon as it starts. The dashboard labels these batches CI and links back to the GitHub Actions attempt, read from GitHub’s environment with no extra setup.
failuresfails the job when any run fails or has a trial that did not pass.strictalso fails when a run or trial is missing or unfinished.neverignores trial results.
To keep the report, upload it with
actions/upload-artifact and if: always().
What runs
A case runs in an empty workspace unless it or its suite names asource, such as repo("acme/api@8f31c4a"). The CLI does not point it at the checked-out commit for you. The checkout above uses the PR head, not GitHub’s merge commit, so the suites and validators are the ones in the PR.
This example skips fork and Dependabot PRs because they don’t receive repository secrets. Keep unit tests in a separate job so they still run. Don’t use pull_request_target to run untrusted suites with a secret.
The job is the PR check. For a separate check named sphynx on the PR head commit, pass github-token: ${{ github.token }} and grant the job checks: write. Its verdict follows the selected gate.
Outside the action, the same command is: