File tree Expand file tree Collapse file tree 1 file changed +4
-3
lines changed Expand file tree Collapse file tree 1 file changed +4
-3
lines changed Original file line number Diff line number Diff line change 11name : Scorecard supply-chain security
22on :
3+ workflow_dispatch :
34 # For Branch-Protection check. Only the default branch is supported. See
45 # https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
56 branch_protection_rule :
3031 persist-credentials : false
3132
3233 - name : " Run analysis"
33- uses : ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3 .1
34+ uses : ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4 .1
3435 with :
3536 results_file : results.sarif
3637 results_format : sarif
4849 # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
4950 # format to the repository Actions tab.
5051 - name : " Upload artifact"
51- uses : actions/upload-artifact@97a0fba1372883ab732affbe8f94b823f91727db # v3.pre.node20
52+ uses : actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
5253 with :
5354 name : SARIF file
5455 path : results.sarif
5758 # Upload the results to GitHub's code scanning dashboard (optional).
5859 # Commenting out will disable upload of results to your repo's Code Scanning dashboard
5960 - name : " Upload to code-scanning"
60- uses : github/codeql-action/upload-sarif@v3
61+ uses : github/codeql-action/upload-sarif@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
6162 with :
6263 sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments