ddd77516efb1393af738e57de9522e091c63c5b6
- Author
- Carlo Sala <carlosalag@protonmail.com>
- Committer
- GitHub <noreply@github.com>
- Date
Message
ci: add scorecard automatic update (#13319)
Diff
1diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
2new file mode 100644
3index 0000000000000000000000000000000000000000..5654fb74b37265d142938ac3e6a212817aa99c11
4--- /dev/null
5+++ b/.github/workflows/scorecard.yml
6@@ -0,0 +1,65 @@
7+# This workflow uses actions that are not certified by GitHub. They are provided
8+# by a third-party and are governed by separate terms of service, privacy
9+# policy, and support documentation.
10+
11+name: Scorecard supply-chain security
12+on:
13+ # For Branch-Protection check. Only the default branch is supported. See
14+ # https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
15+ branch_protection_rule:
16+ # To guarantee Maintained check is occasionally updated. See
17+ # https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
18+ schedule:
19+ - cron: '20 7 * * 2'
20+ push:
21+ branches: ["master"]
22+
23+# Declare default permissions as read only.
24+permissions: read-all
25+
26+jobs:
27+ analysis:
28+ name: Scorecard analysis
29+ runs-on: ubuntu-latest
30+ permissions:
31+ # Needed to upload the results to code-scanning dashboard.
32+ security-events: write
33+ # Needed to publish results and get a badge (see publish_results below).
34+ id-token: write
35+ contents: read
36+ actions: read
37+ # To allow GraphQL ListCommits to work
38+ issues: read
39+ pull-requests: read
40+ # To detect SAST tools
41+ checks: read
42+
43+ steps:
44+ - name: Harden the runner (Audit all outbound calls)
45+ uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
46+ with:
47+ egress-policy: audit
48+
49+ - name: "Checkout code"
50+ uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
51+ with:
52+ persist-credentials: false
53+
54+ - name: "Run analysis"
55+ uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
56+ with:
57+ results_file: results.sarif
58+ results_format: sarif
59+ publish_results: true
60+
61+ - name: "Upload artifact"
62+ uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
63+ with:
64+ name: SARIF file
65+ path: results.sarif
66+ retention-days: 5
67+
68+ - name: "Upload to code-scanning"
69+ uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
70+ with:
71+ sarif_file: results.sarif