GitHub Action
hasanerman/dagsec-action runs the scan on your own GitHub runner: your code never reaches dagsec. The runner downloads the scanner with your API key, scans the checkout, and posts the result as a pull request comment and the job summary.
Setup
- Create an API key.
- Add it as a repository secret named
DAGSEC_API_KEY(Settings → Secrets and variables → Actions). For many repositories, use an organization secret. - Add
.github/workflows/dagsec.yml:
name: dagsec
on: pull_request
permissions:
contents: read
pull-requests: write
id-token: write
jobs:
dagsec:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: hasanerman/dagsec-action@v1
with:
api-key: ${{ secrets.DAGSEC_API_KEY }}Why each line is there
| Line | Why |
|---|---|
fetch-depth: 0 | dagsec reads git history. A shallow clone hides old commits; the Action warns when it sees one. |
pull-requests: write | To post and update the comment. |
id-token: write | Lets GitHub sign a token that proves which repository is running and whether it's public. Required on the Free plan, which scans public repositories only. |
contents: read | For the checkout. |
Inputs
| Input | Default | Meaning |
|---|---|---|
api-key | required | Your dagsec API key. Pass it from a secret. |
fail-under | 40 | Fail when a direct dependency's health score is below this. |
path | . | Directory to scan. |
comment | true | Post the report as a pull request comment (true or false). |
github-token | ${{ github.token }} | Token used to post the comment. |
server | https://app.dagsec.net | dagsec server to download the scanner from. |
Outputs
| Output | Values |
|---|---|
exit-code | 0 passed, 1 findings, 2 scan error |
The job fails when exit-code isn't 0. To report without failing, set continue-on-error: true on the step.
What happens in a run
- Checks the runner is Linux x64 and the key is set.
- Requests a GitHub OIDC token with audience
dagsec, if the workflow allows it. - Downloads the scanner from
serverwith the key and the token. dagsec checks the key, your plan's monthly CI runs, and that the repository is public when you're on the Free plan. A refusal fails the step with the reason, for exampledagsec refused to run (402): scanning private repositories needs the Pro plan. - Scans the checkout. On pull requests only commits since the base are checked for secrets (
--sincethe base SHA). - Writes the Markdown report to the job summary and, on pull requests, creates or updates one comment marked
<!-- dagsec-report -->. - Exits with the scan's exit code.
Each run counts as one CI run for your plan. Leaked GitHub, Stripe and Slack credentials are checked to see if they still work.
Pull requests from forks
GitHub doesn't give secrets to workflows triggered by pull requests from forks, so the Action fails with "api-key is empty". Use the GitHub App for public repositories that take outside contributions.
Pinning
@v1 follows compatible updates. The scanner itself is downloaded fresh on each run, so it always has the current rules.