File tree Expand file tree Collapse file tree 1 file changed +10
-0
lines changed Expand file tree Collapse file tree 1 file changed +10
-0
lines changed Original file line number Diff line number Diff line change 23
23
with :
24
24
persist-credentials : false
25
25
26
+ - uses : actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
27
+ id : create-token
28
+ with :
29
+ # analyzing classic branch protections requires a token with admin read permissions
30
+ # see https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
31
+ # and https://github.com/open-telemetry/community/issues/2769
32
+ app-id : ${{ vars.OSSF_SCORECARD_APP_ID }}
33
+ private-key : ${{ secrets.OSSF_SCORECARD_PRIVATE_KEY }}
34
+
26
35
- uses : ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
27
36
with :
37
+ repo_token : ${{ steps.create-token.outputs.token }}
28
38
results_file : results.sarif
29
39
results_format : sarif
30
40
publish_results : true
You can’t perform that action at this time.
0 commit comments