Skip to content

Scorecards

Scorecards #144

Workflow file for this run

name: "Scorecards"
on:
branch_protection_rule:
schedule:
- cron: "0 0 * * 5"
push:
branches: ["main"]
permissions: "read-all"
jobs:
analyze:
name: Scorecards analysis
runs-on: "ubuntu-latest"
permissions:
security-events: write
id-token: write
contents: read
actions: read
steps:
- name: "Checkout repository"
uses: "actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b"
with:
persist-credentials: false
- name: "Run analysis"
uses: "ossf/scorecard-action@99c53751e09b9529366343771cc321ec74e9bd3d"
with:
results_file: results.sarif
results_format: sarif
repo_token: ${{ secrets.GITHUB_TOKEN }}
publish_results: true