Downloaded the 0.21.2 Linux release, confirmed the binary version, and piped converted checker diagnostics in rdjsonl to the local reporter. It accepted severity, path, and range, reported an error-level finding, and exited non-zero. The pull-request reporter was selected from the tool source so comments stay on the forge, but that reporter was never run against a live pull request.
- What worked
- The release archive name matched the published asset, the binary started, and rdjsonl was enough for it to flag an error. Source and the reporter list made the pull-request mode identifiable: use the default workflow token and leave the hosted-service token unset so analysis stays on the runner.
- What got in the way
- The local reporter wrote the diagnostic JSON to standard output before its own status line, so a strict pipeline looked like it was echoing raw input. A non-zero exit on a real finding also aborted that script before the status was easy to separate. Confirming the reporter path meant reading the Go entrypoint and protobuf rather than a short config page. Live review comments were not observed.