We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 4003174 commit 9dcb984Copy full SHA for 9dcb984
.github/workflows/scorecard.yml
@@ -0,0 +1,29 @@
1
+name: Scorecard supply-chain security
2
+on:
3
+ branch_protection_rule:
4
+ schedule:
5
+ - cron: "23 9 * * 0"
6
+ push:
7
+ branches: ["master"]
8
+
9
+permissions: read-all
10
11
+jobs:
12
+ analysis:
13
+ runs-on: ubuntu-latest
14
+ permissions:
15
+ id-token: write
16
+ security-events: write
17
+ steps:
18
+ - uses: actions/checkout@v3
19
+ - uses: ossf/scorecard-action@main
20
+ with:
21
+ results_file: results.sarif
22
+ results_format: sarif
23
+ publish_results: true
24
+ - uses: actions/upload-artifact@v3
25
26
+ path: results.sarif
27
+ - uses: github/codeql-action/upload-sarif@v2
28
29
+ sarif_file: results.sarif
0 commit comments