varpost/Scout Security Scan

Find hardcoded secrets, injection flaws, missing security headers, and vulnerable dependencies. Free, static, no API keys.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to scan, relative to the workspace.no.
fail-onFail the action when findings at or above this severity exist: critical | high | medium | low | never.nohigh
formatOutput format: sarif | json | markdown.nosarif
upload-sarifUpload results to GitHub Code Scanning (job needs `security-events: write`). Only applies when format is sarif.notrue
installpip requirement to install (advanced — this repo's CI dogfoods a source checkout with '.').noscout-security
namedescription
sarif-filePath to the generated SARIF file (when format is sarif).
exit-codeScout's exit code: 0 clean or below threshold, 1 findings at/above threshold.