123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869 |
- name: Scorecard supply-chain security
- on:
-
-
- branch_protection_rule:
-
-
- schedule:
- - cron: '43 6 * * 5'
- push:
- branches: [ "main" ]
- permissions: read-all
- jobs:
- analysis:
- name: Scorecard analysis
- runs-on: ubuntu-latest
- permissions:
-
- security-events: write
-
- id-token: write
-
-
-
- steps:
- - name: "Checkout code"
- uses: actions/checkout@0ad4b8fadaa221de15dcec353f45205ec38ea70b
- with:
- persist-credentials: false
- - name: "Run analysis"
- uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736
- with:
- results_file: results.sarif
- results_format: sarif
-
-
-
-
-
-
-
-
-
-
-
-
- publish_results: true
-
-
- - name: "Upload artifact"
- uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808
- with:
- name: SARIF file
- path: results.sarif
- retention-days: 5
-
- - name: "Upload to code-scanning"
- uses: github/codeql-action/upload-sarif@d39d31e687223d841ef683f52467bd88e9b21c14
- with:
- sarif_file: results.sarif
|