Skip to content

GitHub Actions Integration

Find the complete Escape GitHub Action in the GitHub Marketplace.

---
name: Escape

on:
  push:
    branches:
      - main

jobs:
  Escape:
    runs-on: ubuntu-latest
    steps:
      - name: Escape Scan
        uses: Escape-Technologies/cli@v1.9.1
        with:
          profile_id: ${{ secrets.ESCAPE_PROFILE_ID }}
          api_key: ${{ secrets.ESCAPE_API_KEY }}
          watch: "true" # to wait for scan completion

Action Inputs

Pin the Action to a release tag, such as @v1.9.1. Its default image tag is derived from the Action ref. If you use a branch ref, set cli_image to an available image tag explicitly.

Input Required Behavior
profile_id Yes Profile ID to scan.
api_key Yes Escape API key.
watch No "true" waits for a terminal scan state; defaults to "false".
configuration_override No Partial JSON scanner configuration for this scan.
cli_image No Override the CLI Docker image.
schema No Passed to profiles update-schema as an upload ID. Upload the schema first with the CLI; local paths and URLs aren't handled by this Action step.

timeout, configuration_override_path, introspection_file, schema_file, and fail_on_severities are deprecated. fail_on_severities doesn't enforce a security gate.

Install and run the CLI binary directly to include GitHub commit metadata automatically or use a quality-gate script. Automatic metadata detection requires the GitHub environment variables, which the Action doesn't forward to its Docker container. watch waits for a terminal scan state; use the script to fail the build for failed or canceled scans or open findings that meet your severity threshold.