{"id":38474403,"url":"https://github.com/pressidium/lftp-mirror-action","last_synced_at":"2026-01-17T05:16:47.067Z","repository":{"id":63353057,"uuid":"555273047","full_name":"pressidium/lftp-mirror-action","owner":"pressidium","description":"🚀 GitHub action to mirror files via SFTP","archived":false,"fork":false,"pushed_at":"2024-01-19T15:42:01.000Z","size":16,"stargazers_count":39,"open_issues_count":3,"forks_count":2,"subscribers_count":4,"default_branch":"master","last_synced_at":"2025-10-27T20:51:38.508Z","etag":null,"topics":["ci-cd","deployment","github-action","lftp"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/pressidium.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null}},"created_at":"2022-10-21T09:01:21.000Z","updated_at":"2025-10-02T08:23:04.000Z","dependencies_parsed_at":"2023-01-11T17:23:57.924Z","dependency_job_id":null,"html_url":"https://github.com/pressidium/lftp-mirror-action","commit_stats":{"total_commits":3,"total_committers":1,"mean_commits":3.0,"dds":0.0,"last_synced_commit":"f9d5c4c8ca3b995545d8dcfd1dc3bad2578ddefb"},"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/pressidium/lftp-mirror-action","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pressidium%2Flftp-mirror-action","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pressidium%2Flftp-mirror-action/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pressidium%2Flftp-mirror-action/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pressidium%2Flftp-mirror-action/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/pressidium","download_url":"https://codeload.github.com/pressidium/lftp-mirror-action/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/pressidium%2Flftp-mirror-action/sbom","scorecard":{"id":744661,"data":{"date":"2025-08-11","repo":{"name":"github.com/pressidium/lftp-mirror-action","commit":"799d35253e69f95d55f58c31f74313a2785e198a"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.8,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/5 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 4 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating alpine:3.15 to alpine:3.15@sha256:19b4bcc4f60e99dd5ebdca0cbce22c503bbcff197549d7e19dab4f22254dc864","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}}]},"last_synced_at":"2025-08-22T18:23:02.595Z","repository_id":63353057,"created_at":"2025-08-22T18:23:02.595Z","updated_at":"2025-08-22T18:23:02.595Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28498603,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-17T04:31:57.058Z","status":"ssl_error","status_checked_at":"2026-01-17T04:31:45.816Z","response_time":85,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ci-cd","deployment","github-action","lftp"],"created_at":"2026-01-17T05:16:44.902Z","updated_at":"2026-01-17T05:16:47.056Z","avatar_url":"https://github.com/pressidium.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# lftp-mirror-action\n\n🚀 GitHub action to mirror files via SFTP.\n\n## Table of Contents\n\n* [Usage](#usage)\n* [Inputs](#inputs)\n* [Bugs \u0026 Features](#bugs--features)\n* [License](#license)\n\n## Usage\n\n```yaml\nname: Deploy via SFTP\non:\n  push:\n    branches:\n      - main\njobs:\n  deploy:\n    name: Deploy\n    runs-on: ubuntu-latest\n    if: github.event_name == 'push'\n    steps:\n      - name: Checkout\n        uses: actions/checkout@v3\n        with:\n          fetch-depth: 0\n\n      - name: Deploy files via SFTP\n        uses: pressidium/lftp-mirror-action@v1\n        with:\n          # SFTP credentials\n          host: ${{ secrets.SFTP_HOST }}\n          port: ${{ secrets.SFTP_PORT }}\n          user: ${{ secrets.SFTP_USER }}\n          pass: ${{ secrets.SFTP_PASS }}\n          # lftp settings\n          onlyNewer: true\n          settings: 'sftp:auto-confirm=yes'\n          # Mirror command options\n          localDir: '.'\n          remoteDir: '/var/www/html/example.com/public'\n          reverse: true\n          ignoreFile: '.lftp_ignore'\n          options: '--verbose'\n```\n\n## Inputs\n\n| Parameter           | Description                                                               | Required | Default            |\n|---------------------|---------------------------------------------------------------------------|----------|--------------------|\n| `host`              | The hostname of the SFTP server                                           | Yes      | N/A                |\n| `port`              | The port of the SFTP server                                               | No       | `'22'`             |\n| `user`              | The username to use for authentication                                    | Yes      | N/A                |\n| `pass`              | The password to use for authentication                                    | Yes      | N/A                |\n| `forceSSL`          | Refuse to send password in clear when server does not support SSL         | No       | `'true'`           |\n| `verifyCertificate` | Verify server’s certificate to be signed by a known Certificate Authority | No       | `'true'`           |\n| `fingerprint`       | Key fingerprint of the host we want to connect to                         | No       | `''`               |\n| `onlyNewer`         | Only transfer files that are newer than the ones on the remote server     | No       | `'true'`           |\n| `restoreMTime`      | Restore the modification time of the files                                | No       | `'true'`           |\n| `parallel`          | Number of parallel transfers                                              | No       | `'1'`              |\n| `settings`          | Any additional lftp settings to configure                                 | No       | `''`               |\n| `localDir`          | The local directory to copy from (assuming `reverse` is set to `true`)    | No       | `'.'`              |\n| `remoteDir`         | The remote directory to copy to (assuming `reverse` is set to `true`)     | No       | `'/var/www/html/'` |\n| `reverse`           | Whether to copy from the remote to the local or the other way around      | No       | `'true'`           |\n| `ignoreFile`        | The name of the file to use as the ignore list                            | No       | `'.lftp_ignore'`   |\n| `options`           | Any additional `mirror` command options to configure                      | No       | `''`               |\n\n### Fingerprint\n\nOmitting the `fingerprint` input, defaults to accepting any fingerprint\n(i.e. automatically adding the host/port to the `known_hosts` file)\n\n### Restoring modification times\n\n:warning: Read this section if `lftp-mirror-action` uploads _all_ files every time it runs.\n\nGit does not preserve the original modification time of committed files.\nWhen repositories are cloned, branches are checked out, etc., the modification time\nof the files is updated to the current time. This means that the modification time\nof the files on the GitHub runner will always be newer than the files on the SFTP server,\nwhich will result in the `mirror` command always uploading all files (since `lftp` determines\nwhether a file has changed based on its file size and timestamp).\n\nTo prevent this, if `onlyNewer` is set to `true`, we restore the modification time of the files\nbased on the date of the most recent commit that modified them. You can disable this behavior\nby setting `restoreMTime` to `false` (useful if you've already run an action like\n[`git-restore-mtime-action`](https://github.com/chetan/git-restore-mtime-action)\nin your GitHub Actions workflow).\n\nIf you're using [`actions/checkout`](https://github.com/actions/checkout) ≥ `v2` you _must_ set\n`fetch-depth` to `0` in order to fetch the entire Git history.\n\n## Bugs \u0026 Features\n\nIf you've spotted any bugs, or would like to request additional features from this\nGitHub Action, please [open an issue](https://github.com/pressidium/lftp-mirror-action/issues).\n\n## License\n\nThe MIT License, check the `LICENSE` file.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpressidium%2Flftp-mirror-action","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fpressidium%2Flftp-mirror-action","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpressidium%2Flftp-mirror-action/lists"}