File tree 1 file changed +47
-0
lines changed
1 file changed +47
-0
lines changed Original file line number Diff line number Diff line change
1
+ name : OSSF Scorecard
2
+
3
+ on :
4
+ push :
5
+ branches :
6
+ - main
7
+ schedule :
8
+ - cron : " 43 6 * * 5" # weekly at 06:43 (UTC) on Friday
9
+ workflow_dispatch :
10
+
11
+ permissions : read-all
12
+
13
+ jobs :
14
+ analysis :
15
+ runs-on : ubuntu-latest
16
+ permissions :
17
+ # Needed for Code scanning upload
18
+ security-events : write
19
+ # Needed for GitHub OIDC token if publish_results is true
20
+ id-token : write
21
+ steps :
22
+ - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
23
+ with :
24
+ persist-credentials : false
25
+
26
+ - uses : ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
27
+ with :
28
+ results_file : results.sarif
29
+ results_format : sarif
30
+ publish_results : true
31
+
32
+ # Upload the results as artifacts (optional). Commenting out will disable
33
+ # uploads of run results in SARIF format to the repository Actions tab.
34
+ # https://docs.github.com/en/actions/advanced-guides/storing-workflow-data-as-artifacts
35
+ - name : " Upload artifact"
36
+ uses : actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # v4.6.0
37
+ with :
38
+ name : SARIF file
39
+ path : results.sarif
40
+ retention-days : 5
41
+
42
+ # Upload the results to GitHub's code scanning dashboard (optional).
43
+ # Commenting out will disable upload of results to your repo's Code Scanning dashboard
44
+ - name : " Upload to code-scanning"
45
+ uses : github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
46
+ with :
47
+ sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments