Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
action-octoscan — 📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions. | Kitploit
Tools/GitHubGitHub/synacktiv/action-octoscan
Vulnerability ScannersStatic Code Analysis (SAST)Code AnalysisDevSecOpsMisconfiguration
GitHubsynacktiv/action-octoscan

action-octoscan

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

View Repository
26221 year agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
📦 :octocat:

action octoscan

A GitHub Action that performs a security scan of your GitHub actions.

This action is based on octoscan


  • 🤸 Usage
  • Customizing
    • inputs
    • outputs
    • Permissions

🤸 Usage

Here is a basic example of how to use this action. This will work for both push and pull_request events.

---
name: Octoscan

on:
  workflow_dispatch:
  pull_request:
    paths:
      - '.github/workflows/*'
  push:
    paths:
      - '.github/workflows/*'

permissions:
  security-events: write
  actions: read
  contents: read

jobs:
  octoscan:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4

      - id: octoscan
        name: Run octoscan
        uses: synacktiv/action-octoscan@v1

      - name: Upload SARIF file to GitHub
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: "${{steps.octoscan.outputs.sarif_output}}"
          category: octoscan

Security results can the be reviewed in the code security tab if you have write access on the target repository: code security

Or directly in the pull request: code security

Customizing

inputs

Inputs are based on the options of octoscan, you can find them here.

The following are optional as step.with keys:

NameTypeDescription
workdirStringWorking directory relative to the root directory.
filter_triggersStringScan workflows with specific triggers (comma separated list: "push,pull_request_target" or pre-configured: external/allnopr). Default is external.
filter_runBooleanSearch for expression injection only in run shell scripts. Default is true
ignoreStringRegular expression matching to error messages you want to ignore.
disable_rulesStringDisable specific rules. Split on ",". Can't be used with enable_rules.
enable_rulesStringEnable specific rules, this will disable all other rules. Split on ",". Can't be used with disable_rules.

💡 It's not possible to use enable_rules and disable_rules at the same time.

outputs

The following outputs can be accessed via ${{ steps.<step-id>.outputs }} from this action

NameTypeDescription
sarif_outputStringThe name of the file containing the sarif output.

Permissions

This Action requires the following permissions on the GitHub integration token:

permissions:
  security-events: write
  actions: read
  contents: read

security-events is used to push the output of octoscan to GitHub code scanning.

Download Tool