We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 07fbe08 commit 01ac972Copy full SHA for 01ac972
1 file changed
.github/workflows/scorecard.yml
@@ -0,0 +1,32 @@
1
+name: OpenSSF Scorecard
2
+on:
3
+ push:
4
+ branches: [main]
5
+ schedule:
6
+ - cron: "0 6 * * 1"
7
+ workflow_dispatch:
8
+
9
+permissions: read-all
10
11
+jobs:
12
+ analysis:
13
+ name: Scorecard analysis
14
+ runs-on: ubuntu-latest
15
+ permissions:
16
+ security-events: write
17
+ id-token: write
18
+ steps:
19
+ - uses: actions/checkout@v4
20
+ with: { persist-credentials: false }
21
+ - uses: ossf/scorecard-action@v2.4.1
22
+ with:
23
+ results_file: results.sarif
24
+ results_format: sarif
25
+ publish_results: true
26
+ - uses: actions/upload-artifact@v4
27
28
+ name: SARIF file
29
+ path: results.sarif
30
+ - uses: github/codeql-action/upload-sarif@v3
31
32
+ sarif_file: results.sarif
0 commit comments