finds.dev← search

// the find

appleboy/scp-action

★ 1,580 · Shell · MIT · updated Aug 2026

GitHub Action that copy files and artifacts via SSH.

A Docker-based GitHub Action for copying files to remote servers over SSH, wrapping appleboy's drone-scp binary. It's for teams doing simple server deploys (copy a build artifact to a VM) who don't want to hand-roll scp/rsync steps in CI, and who are fine with the connectivity model.

The config surface covers real-world deploy needs: multi-host comma-separated targets, SSH proxy/jump host support, and incremental transfer via the changed-files pattern shown in the docs. It ships trivy scanning and goreleaser in CI, which is more supply-chain hygiene than most actions in this niche bother with. Password auth, host key fingerprint checks, and tar-based transfer with dereference options handle the annoying edge cases (Windows targets, symlinks) that trip up naive scp wrappers.

The actual transfer logic isn't in this repo — it pulls a specific drone-scp binary version at runtime, so you're trusting a release artifact outside the action.yml/entrypoint.sh you can actually read here; the 'version' input to pin that binary isn't documented with a default or a changelog link. Docker-only means every run pays image pull time and you can't use it on a non-Docker self-hosted runner. Host key fingerprint verification and the `rm` (wipe target dir) flag are both off by default and easy to skip, so the common path is still MITM-exposed and the destructive option is one typo away from nuking the wrong directory. The 'tests' directory is just sample fixture files, not a real test suite — whatever correctness testing exists lives upstream in drone-scp, not here.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →