// the find
appleboy/scp-action
GitHub Action that copy files and artifacts via SSH.
A Docker-based GitHub Action for copying files to remote servers over SSH, wrapping appleboy's drone-scp binary. It's for teams doing simple server deploys (copy a build artifact to a VM) who don't want to hand-roll scp/rsync steps in CI, and who are fine with the connectivity model.
The config surface covers real-world deploy needs: multi-host comma-separated targets, SSH proxy/jump host support, and incremental transfer via the changed-files pattern shown in the docs. It ships trivy scanning and goreleaser in CI, which is more supply-chain hygiene than most actions in this niche bother with. Password auth, host key fingerprint checks, and tar-based transfer with dereference options handle the annoying edge cases (Windows targets, symlinks) that trip up naive scp wrappers.
The actual transfer logic isn't in this repo — it pulls a specific drone-scp binary version at runtime, so you're trusting a release artifact outside the action.yml/entrypoint.sh you can actually read here; the 'version' input to pin that binary isn't documented with a default or a changelog link. Docker-only means every run pays image pull time and you can't use it on a non-Docker self-hosted runner. Host key fingerprint verification and the `rm` (wipe target dir) flag are both off by default and easy to skip, so the common path is still MITM-exposed and the destructive option is one typo away from nuking the wrong directory. The 'tests' directory is just sample fixture files, not a real test suite — whatever correctness testing exists lives upstream in drone-scp, not here.