ddd77516efb1393af738e57de9522e091c63c5b6

Author
Carlo Sala <carlosalag@protonmail.com>
Committer
GitHub <noreply@github.com>
Date

Message

ci: add scorecard automatic update (#13319)

Diff

 1diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
 2new file mode 100644
 3index 0000000000000000000000000000000000000000..5654fb74b37265d142938ac3e6a212817aa99c11
 4--- /dev/null
 5+++ b/.github/workflows/scorecard.yml
 6@@ -0,0 +1,65 @@
 7+# This workflow uses actions that are not certified by GitHub. They are provided
 8+# by a third-party and are governed by separate terms of service, privacy
 9+# policy, and support documentation.
10+
11+name: Scorecard supply-chain security
12+on:
13+  # For Branch-Protection check. Only the default branch is supported. See
14+  # https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
15+  branch_protection_rule:
16+  # To guarantee Maintained check is occasionally updated. See
17+  # https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
18+  schedule:
19+    - cron: '20 7 * * 2'
20+  push:
21+    branches: ["master"]
22+
23+# Declare default permissions as read only.
24+permissions: read-all
25+
26+jobs:
27+  analysis:
28+    name: Scorecard analysis
29+    runs-on: ubuntu-latest
30+    permissions:
31+      # Needed to upload the results to code-scanning dashboard.
32+      security-events: write
33+      # Needed to publish results and get a badge (see publish_results below).
34+      id-token: write
35+      contents: read
36+      actions: read
37+      # To allow GraphQL ListCommits to work
38+      issues: read
39+      pull-requests: read
40+      # To detect SAST tools
41+      checks: read
42+
43+    steps:
44+      - name: Harden the runner (Audit all outbound calls)
45+        uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1
46+        with:
47+          egress-policy: audit
48+
49+      - name: "Checkout code"
50+        uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
51+        with:
52+          persist-credentials: false
53+
54+      - name: "Run analysis"
55+        uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
56+        with:
57+          results_file: results.sarif
58+          results_format: sarif
59+          publish_results: true
60+
61+      - name: "Upload artifact"
62+        uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
63+        with:
64+          name: SARIF file
65+          path: results.sarif
66+          retention-days: 5
67+
68+      - name: "Upload to code-scanning"
69+        uses: github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3 # v3.30.3
70+        with:
71+          sarif_file: results.sarif