Skip to content

Commit 626d656

Browse files
authored
Merge pull request #70 from hyphae/axmsoftware-patch-4
Update Scorecard workflow dependencies and permissions
2 parents 8638efe + dccb217 commit 626d656

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

.github/workflows/scorecard.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,8 @@ on:
1515
branches: [ "add-license-1" ]
1616

1717
# Declare default permissions as read only.
18-
permissions: read-all
18+
permissions:
19+
contents: read
1920

2021
jobs:
2122
analysis:
@@ -32,12 +33,12 @@ jobs:
3233

3334
steps:
3435
- name: "Checkout code"
35-
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
36+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3637
with:
3738
persist-credentials: false
3839

3940
- name: "Run analysis"
40-
uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1
41+
uses: ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1
4142
with:
4243
results_file: results.sarif
4344
results_format: sarif
@@ -59,8 +60,7 @@ jobs:
5960
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6061
# format to the repository Actions tab.
6162
- name: "Upload artifact"
62-
uses: actions/upload-artifact@97a0fba1372883ab732affbe8f94b823f91727db # v3.pre.node20
63-
with:
63+
uses: actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
6464
name: SARIF file
6565
path: results.sarif
6666
retention-days: 10

0 commit comments

Comments
 (0)