File tree Expand file tree Collapse file tree 1 file changed +47
-0
lines changed Expand file tree Collapse file tree 1 file changed +47
-0
lines changed Original file line number Diff line number Diff line change 1+ name : OSSF Scorecard
2+
3+ on :
4+ push :
5+ branches :
6+ - main
7+ schedule :
8+ - cron : " 43 6 * * 5" # weekly at 06:43 (UTC) on Friday
9+ workflow_dispatch :
10+
11+ permissions : read-all
12+
13+ jobs :
14+ analysis :
15+ runs-on : ubuntu-latest
16+ permissions :
17+ # Needed for Code scanning upload
18+ security-events : write
19+ # Needed for GitHub OIDC token if publish_results is true
20+ id-token : write
21+ steps :
22+ - uses : actions/checkout@v4
23+ with :
24+ persist-credentials : false
25+
26+ - uses : ossf/scorecard-action@v2
27+ with :
28+ results_file : results.sarif
29+ results_format : sarif
30+ publish_results : true
31+
32+ # Upload the results as artifacts (optional). Commenting out will disable
33+ # uploads of run results in SARIF format to the repository Actions tab.
34+ # https://docs.github.com/en/actions/advanced-guides/storing-workflow-data-as-artifacts
35+ - name : " Upload artifact"
36+ uses : actions/upload-artifact@v4
37+ with :
38+ name : SARIF file
39+ path : results.sarif
40+ retention-days : 5
41+
42+ # Upload the results to GitHub's code scanning dashboard (optional).
43+ # Commenting out will disable upload of results to your repo's Code Scanning dashboard
44+ - name : " Upload to code-scanning"
45+ uses : github/codeql-action/upload-sarif@v3
46+ with :
47+ sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments