Aether Actions · Production

Security and build checks for the commit you are shipping.

Select a connected GitHub repository. Aether resolves its default-branch head to an exact commit, shows the maximum UVT cost, and runs authorized checks on Aether infrastructure. Results return as an integrity-checked Aether report and a GitHub Check.

  • Exact-commit execution
  • Upfront UVT ceiling
  • Integrity-checked results
  • 0 UVT when unsupported
Aether ActionsProduction
RepositoryAetherAI3/AETHER-CLOUDcommit c694c88
Compatible assurance profileaethercloud/[email protected]
Supported
5 locked routes54 checks1 exact commit
Example quotePredator Security
Estimated UVT
50,000
Maximum authorization
110,000
Authorize up to 110,000 UVTNothing runs or reserves UVT before approval.
Result delivered · Integrity-checked report + GitHub Check

The product relationship

Actions runs the work. Predator defines the security check.

One hosted execution layer, one locked security operation, and one result bound to the commit Aether resolved.

01Hosted execution

Aether Actions

The repository execution plane.

It handles GitHub access, compatibility, authorization, hosted execution, billing boundaries, and delivery of results.

02Locked operation

Predator Security

A security check that runs on Actions.

Its assurance profile fixes the routes, commands, environment, verdict rules, and runner class outside the repository being tested.

  1. GitHub repositoryexact commit
  2. Aether Actionsquote + execution
  3. Predator Securitylocked profile
  4. Aether + GitHubreport + Check
Separate local tool

Predator CLI

Local software analysis. It is not the hosted check and does not produce the same hosted evidence.

Operator-led engagement

Predator Red Team

Human-run, scoped, and scheduled. It is not an automated UVT product.

From commit to result

A run stays understandable at every step.

Compatibility comes before cost. Cost comes before authorization. Execution starts only after both are clear.

  1. 01

    Select

    Choose a connected repository. Aether resolves its default-branch head to one exact commit.

  2. 02

    Check compatibility

    Aether checks support before quoting. This costs 0 UVT.

  3. 03

    Review the quote

    See the estimated price and the hard maximum before anything runs.

  4. 04

    Authorize and run

    Execution and UVT reservation begin only after explicit authorization.

  5. 05

    Receive the result

    Get the integrity-checked report and GitHub Check for that exact commit.

In a manual browser run, a changed assurance profile or a newly required maximum above the approved ceiling is refused and sent back for a fresh quote.

Predator Security

A tamper-resistant security check for production code.

The production profile replays registered security routes against one exact commit, with the operation controlled outside the repository under test.

Production profileaethercloud/[email protected]
5
locked assurance routes
54
individual checks
1
exact commit per result
0
UVT when unsupported

The security boundary

The repository cannot choose the verifier image, commands, route catalog, verdict reducer, or price—and repository code cannot write its own successful verdict.

What a verified result means

The registered routes completed against the identified commit. It does not claim the repository is vulnerability-free, and it does not apply to later commits.

UVT billing and authorization

You approve the maximum before anything runs.

Repository access and spend authorization are separate decisions. The quote makes the boundary visible before Aether reserves or executes anything.

  • GitHub connection grants repository access, not permission to spend UVT.
  • Compatibility checking happens before a quote and costs 0 UVT.
  • Every eligible run shows an estimate and hard maximum.
  • Execution and reservation begin only after explicit authorization.
  • A run cannot exceed the maximum you approved.
  • Manual profile changes or a newly required higher maximum trigger a fresh quote.
  • Push and pull-request runs require an owner-saved maximum UVT per run.
Example quotePredator Security
Estimated UVT
50,000
Maximum authorization
110,000
Authorize up to 110,000 UVTNothing runs or reserves UVT before approval.

Current production example: a 300-second estimate with a 900-second execution ceiling. No account balance is shown.

Human-readable outcomes

A result says what happened—not more.

Infrastructure trouble is not labeled as a vulnerability, and a clean run is scoped to the registered routes and exact commit.

Verified

Predator Verified

Registered routes completed without a finding for this exact commit.

Findings

Predator found issues

Predator produced a security result about the code.

Did not verify

Predator did not verify

One or more routes could not complete. This is not presented as a code vulnerability.

Did not run

Predator was not run

Nothing executed and nothing was verified.

The immutable receipt remains the historical record; the current interface is a human-readable projection of that record, not a rewrite of it.

Repository coverage

Is my repository supported?

Aether checks repository coverage before presenting a Predator quote. When you authorize, it validates the resolved commit before reserving UVT.

Supported

An approved profile covers this repository.

Run action available

Onboarding required

No approved profile covers this repository yet.

Request an assurance profile · 0 UVT

Unsupported

The repository cannot be verified by a current Predator profile.

Request an assurance profile · 0 UVT

Temporarily unavailable

The profile exists, but hosted capacity or another dependency is unavailable.

Follow the in-product recovery step · 0 UVT

Current Predator coverage

Production coverage currently consists of aethercloud/[email protected]. Customer assurance profiles are Aether-authored, private preview, and not self-service. No turnaround time is promised.

Request an assurance profile

Hosted Build & Test is separate. It runs a repository’s configured checks through Actions and does not depend on Predator profile coverage where the production deployment has enabled that repository.

Product status

What is available today.

Production, preview, unsupported, and in-development capabilities are kept distinct so you can plan against what actually exists.

CapabilityStatusDetail
Aether Actions hosted executionProductionQuote, authorization, and exact-commit execution on Aether infrastructure for repositories enabled in the production deployment.
AetherCloud Core Predator profileProductionaethercloud/[email protected] — 5 routes, 54 checks, on the AetherCloud backend surface.
Approved customer assurance profilesPrivate previewProfiles are Aether-authored per repository. There is no self-serve path and no committed turnaround time.
Predator scanning for repositories without a profileUnsupportedThe current verifier is AetherCloud-specific. A repository with no approved profile is refused before any UVT is reserved.
Hosted Build & TestProductionRuns a repository's configured checks independently of Predator profiles. Repository availability remains deployment-controlled.
Pull-request and push automationProductionOff until the owner saves Actions settings with an explicit maximum UVT per run. Connecting GitHub never authorizes spend, and repository availability remains deployment-controlled.
Public certificate share and verificationProductionEligible verified runs can issue, publish, verify, and revoke a signed certificate. Public verification is currently a safe JSON response rather than a branded page.
Aether Code remediation handoffIn developmentA safe intake link exists, but the receiving side does not yet open the repository at the exact verified commit.
FAQ

Frequently asked questions

  • Only if an approved Aether assurance profile covers it. The current verifier is specific to the AetherCloud backend surface, so most repositories answer "onboarding required" today. Aether checks before you are quoted, so finding out costs nothing and reserves nothing.