r12habh/ActionScope

Map the AWS blast radius of GitHub Actions workflows and AI agent configs

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to the repository root to scanno.
fail-onFail the action if overall risk is at or above this level (critical, high, medium, low)nohigh
output-formatOutput format: terminal, json, markdown, or sarifnoterminal
upload-sarifUpload SARIF results to GitHub Code Scanningnofalse
resolve-pinsResolve unpinned action tags to current SHA via GitHub APInofalse
offlineDisable scan-time GitHub and AWS API callsnofalse
save-stateSave scan state for delta comparison in future scansnofalse
load-stateCompare against previous scan state for delta reportingnofalse
state-artifact-nameGitHub Actions artifact name for persisting scan statenoactionscope-state
comment-prPost findings as a PR comment (requires pull-requests: write permission)nofalse
github-tokenGitHub token for PR comments, pin resolution, and external reusable workflow inspectionno${{ github.token }}
versionActionScope version to install (default: latest)no""
namedescription
overall-riskThe overall risk level found (critical, high, medium, low, info)
findings-jsonJSON string of all findings
credential-sources-countNumber of AWS credential sources found