Skip to content

GitHub Action ​

hasanerman/dagsec-action runs the scan on your own GitHub runner: your code never reaches dagsec. The runner downloads the scanner with your API key, scans the checkout, and posts the result as a pull request comment and the job summary.

Setup ​

  1. Create an API key.
  2. Add it as a repository secret named DAGSEC_API_KEY (Settings → Secrets and variables → Actions). For many repositories, use an organization secret.
  3. Add .github/workflows/dagsec.yml:
yaml
name: dagsec
on: pull_request
permissions:
  contents: read
  pull-requests: write
  id-token: write
jobs:
  dagsec:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      - uses: hasanerman/dagsec-action@v1
        with:
          api-key: ${{ secrets.DAGSEC_API_KEY }}

Why each line is there ​

LineWhy
fetch-depth: 0dagsec reads git history. A shallow clone hides old commits; the Action warns when it sees one.
pull-requests: writeTo post and update the comment.
id-token: writeLets GitHub sign a token that proves which repository is running and whether it's public. Required on the Free plan, which scans public repositories only.
contents: readFor the checkout.

Inputs ​

InputDefaultMeaning
api-keyrequiredYour dagsec API key. Pass it from a secret.
fail-under40Fail when a direct dependency's health score is below this.
path.Directory to scan.
commenttruePost the report as a pull request comment (true or false).
github-token${{ github.token }}Token used to post the comment.
serverhttps://app.dagsec.netdagsec server to download the scanner from.

Outputs ​

OutputValues
exit-code0 passed, 1 findings, 2 scan error

The job fails when exit-code isn't 0. To report without failing, set continue-on-error: true on the step.

What happens in a run ​

  1. Checks the runner is Linux x64 and the key is set.
  2. Requests a GitHub OIDC token with audience dagsec, if the workflow allows it.
  3. Downloads the scanner from server with the key and the token. dagsec checks the key, your plan's monthly CI runs, and that the repository is public when you're on the Free plan. A refusal fails the step with the reason, for example dagsec refused to run (402): scanning private repositories needs the Pro plan.
  4. Scans the checkout. On pull requests only commits since the base are checked for secrets (--since the base SHA).
  5. Writes the Markdown report to the job summary and, on pull requests, creates or updates one comment marked <!-- dagsec-report -->.
  6. Exits with the scan's exit code.

Each run counts as one CI run for your plan. Leaked GitHub, Stripe and Slack credentials are checked to see if they still work.

Pull requests from forks ​

GitHub doesn't give secrets to workflows triggered by pull requests from forks, so the Action fails with "api-key is empty". Use the GitHub App for public repositories that take outside contributions.

Pinning ​

@v1 follows compatible updates. The scanner itself is downloaded fresh on each run, so it always has the current rules.