Skip to content

Commit 45ea931

Browse files
authored
Fix OSSF scorecard branch protection check (#2015)
1 parent 5aaf88f commit 45ea931

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

.github/workflows/ossf-scorecard.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,8 +23,18 @@ jobs:
2323
with:
2424
persist-credentials: false
2525

26+
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
27+
id: create-token
28+
with:
29+
# analyzing classic branch protections requires a token with admin read permissions
30+
# see https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
31+
# and https://github.com/open-telemetry/community/issues/2769
32+
app-id: ${{ vars.OSSF_SCORECARD_APP_ID }}
33+
private-key: ${{ secrets.OSSF_SCORECARD_PRIVATE_KEY }}
34+
2635
- uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
2736
with:
37+
repo_token: ${{ steps.create-token.outputs.token }}
2838
results_file: results.sarif
2939
results_format: sarif
3040
publish_results: true

0 commit comments

Comments
 (0)