Skip to content

rebranding

rebranding #61

Workflow file for this run

name: OpenSSF Scorecard
on:
push:
branches: [main]
paths:
- 'src/**'
- 'package*.json'
- '.github/**'
schedule:
- cron: '0 6 * * 1'
concurrency:
group: scorecard-${{ github.ref }}
cancel-in-progress: true
permissions: read-all
jobs:
analyze:
name: Scorecard Analysis
runs-on: ubuntu-latest
permissions:
security-events: write
id-token: write
contents: read
actions: read
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
with:
persist-credentials: false
- name: Run Scorecard
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: scorecard.sarif
results_format: sarif
publish_results: true
repo_token: ${{ secrets.GITHUB_TOKEN }}
- name: Upload SARIF to GitHub Security tab
uses: github/codeql-action/upload-sarif@89a39a4e59826350b863aa6b6252a07ad50cf83e # v4
with:
sarif_file: scorecard.sarif
category: openssf-scorecard