GitHub Actions Integration¶
Find the complete Escape GitHub Action in the GitHub Marketplace.
---
name: Escape
on:
push:
branches:
- main
jobs:
Escape:
runs-on: ubuntu-latest
steps:
- name: Escape Scan
uses: Escape-Technologies/cli@v1.9.1
with:
profile_id: ${{ secrets.ESCAPE_PROFILE_ID }}
api_key: ${{ secrets.ESCAPE_API_KEY }}
watch: "true" # to wait for scan completion
Action Inputs¶
Pin the Action to a release tag, such as @v1.9.1. Its default image tag is derived from the Action ref. If you use a branch ref, set cli_image to an available image tag explicitly.
| Input | Required | Behavior |
|---|---|---|
profile_id |
Yes | Profile ID to scan. |
api_key |
Yes | Escape API key. |
watch |
No | "true" waits for a terminal scan state; defaults to "false". |
configuration_override |
No | Partial JSON scanner configuration for this scan. |
cli_image |
No | Override the CLI Docker image. |
schema |
No | Passed to profiles update-schema as an upload ID. Upload the schema first with the CLI; local paths and URLs aren't handled by this Action step. |
timeout, configuration_override_path, introspection_file, schema_file, and fail_on_severities are deprecated. fail_on_severities doesn't enforce a security gate.
Install and run the CLI binary directly to include GitHub commit metadata automatically or use a quality-gate script. Automatic metadata detection requires the GitHub environment variables, which the Action doesn't forward to its Docker container. watch waits for a terminal scan state; use the script to fail the build for failed or canceled scans or open findings that meet your severity threshold.