Lsec Action

lsec GitHub Action

Shell

Project Details

lsec — Laravel Security Audit (GitHub Action)

A GitHub Action that runs lsec — the Laravel
security audit CLI — against your repository, uploads results to GitHub Code
Scanning as SARIF, and posts a summary comment on pull requests.

lsec ships 61 rules across 8 categories: env, auth, injection, http,
storage, deps, secrets, logging. See the
lsec README for the full rule list.


Quick start

# .github/workflows/lsec.yml
name: lsec

on:
  push:
    branches: [main]
  pull_request:

permissions:
  contents: read
  security-events: write   # required for SARIF upload
  pull-requests: write     # required for the PR summary comment

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: AfaanBilal/lsec-action@v1

That defaults to scanning the repository root, failing on high or above,
uploading SARIF, and commenting on pull requests.


Inputs

NameDefaultDescription
path.Path to the Laravel project root.
versionlatestlsec release version (e.g. 0.1.4) or latest.
fail-onhighMinimum severity that fails the job: critical | high | medium | low | info.
min-confidence0.7Minimum confidence score for reported findings (0.0 – 1.0).
baseline""Path to a baseline file used to suppress known findings.
only""Comma-separated rule categories to include (e.g. env,secrets,injection).
skip""Comma-separated rule categories to skip.
upload-sariftrueUpload SARIF to GitHub Code Scanning.
post-commenttruePost (or update) a summary comment on pull requests.
sarif-outputlsec.sarifPath to write the SARIF report.
json-outputlsec-report.jsonPath to write the JSON report.

Outputs

NameDescription
resultpass or fail (against the fail-on threshold).
exit-codeRaw lsec exit code (0 clean, 1 threshold breached, 2 runtime error).
findings-countTotal findings reported.
critical-countNumber of CRITICAL findings.
high-countNumber of HIGH findings.
medium-countNumber of MEDIUM findings.
low-countNumber of LOW findings.
info-countNumber of INFO findings.
sarif-pathPath to the generated SARIF file.
json-pathPath to the generated JSON report.

Permissions

PermissionWhy
contents: readCheckout the repository.
security-events: writeUpload SARIF to Code Scanning. Omit if upload-sarif: false.
pull-requests: writePost the PR summary comment. Omit if post-comment: false.

Code Scanning is free on public repositories. Private repositories require
GitHub Advanced Security.


Examples

Scan a sub-directory

- uses: AfaanBilal/lsec-action@v1
  with:
    path: ./api

Fail only on critical findings

- uses: AfaanBilal/lsec-action@v1
  with:
    fail-on: critical

Pin a specific lsec version

- uses: AfaanBilal/lsec-action@v1
  with:
    version: 0.1.4

Use a baseline to suppress known findings

- uses: AfaanBilal/lsec-action@v1
  with:
    baseline: ci/lsec-baseline.json

Generate the baseline locally with lsec baseline write . and commit it.

Limit to a few rule categories

- uses: AfaanBilal/lsec-action@v1
  with:
    only: env,secrets,deps

Skip categories you don't care about

- uses: AfaanBilal/lsec-action@v1
  with:
    skip: logging

Disable SARIF upload (e.g. private repo without Advanced Security)

- uses: AfaanBilal/lsec-action@v1
  with:
    upload-sarif: false

Run as a non-blocking advisory check

- uses: AfaanBilal/lsec-action@v1
  id: lsec
  continue-on-error: true
  with:
    fail-on: info

- run: echo "lsec found ${{ steps.lsec.outputs.findings-count }} issue(s)"

Use outputs in subsequent steps

- uses: AfaanBilal/lsec-action@v1
  id: lsec

- name: Notify on critical findings
  if: steps.lsec.outputs.critical-count != '0'
  run: ./notify-security.sh "${{ steps.lsec.outputs.critical-count }} critical findings"

How it works

  1. Install — downloads the matching lsec release binary into
    $RUNNER_TEMP/lsec-bin/ and adds it to PATH.
  2. Scan (JSON) — runs lsec scan ... --ci --format json. The lsec exit
    code is the source of truth for pass / fail.
  3. Scan (SARIF) — runs lsec scan ... --format sarif (only when
    upload-sarif: true).
  4. Upload SARIF — hands the report to github/codeql-action/upload-sarif@v3
    so findings appear inline on PRs and in the Security tab.
  5. PR comment — posts (or updates) a single sticky comment with the
    severity table and top findings.
  6. Enforce — exits non-zero when result == fail, failing the job.

Platform support

OS / archSupported
ubuntu-latest (x86_64)✅
Linux ARM64✅
macos-latest (Apple Silicon)✅
macos-13 (Intel)✅
windows-latest✅ (x86_64 only)

Versioning

This action follows semantic versioning. Pin to:

  • @v1 — latest 1.x release (recommended).
  • @v1.2.3 — exact release.
  • @main — bleeding edge (not recommended for production).

The version input controls which lsec CLI release is downloaded; it is
independent of the action version.

License

MIT — see lsec for the upstream tool.

Action authored by Afaan Bilal.

License

MIT License

Copyright (c) 2026 Afaan Bilal

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.