Parent directory

scorecard.yml

2171 bytes
 1# This workflow uses actions that are not certified by GitHub. They are provided
 2# by a third-party and are governed by separate terms of service, privacy
 3# policy, and support documentation.
 4
 5name: Scorecard supply-chain security
 6on:
 7  # For Branch-Protection check. Only the default branch is supported. See
 8  # https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
 9  branch_protection_rule:
10  # To guarantee Maintained check is occasionally updated. See
11  # https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
12  schedule:
13    - cron: '20 7 * * 2'
14  push:
15    branches: ["master"]
16
17# Declare default permissions as read only.
18permissions: read-all
19
20jobs:
21  analysis:
22    name: Scorecard analysis
23    runs-on: ubuntu-latest
24    permissions:
25      # Needed to upload the results to code-scanning dashboard.
26      security-events: write
27      # Needed to publish results and get a badge (see publish_results below).
28      id-token: write
29      contents: read
30      actions: read
31      # To allow GraphQL ListCommits to work
32      issues: read
33      pull-requests: read
34      # To detect SAST tools
35      checks: read
36
37    steps:
38      - name: Harden the runner (Audit all outbound calls)
39        uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
40        with:
41          egress-policy: audit
42
43      - name: "Checkout code"
44        uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
45        with:
46          persist-credentials: false
47
48      - name: "Run analysis"
49        uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4
50        with:
51          results_file: results.sarif
52          results_format: sarif
53          publish_results: true
54
55      - name: "Upload artifact"
56        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
57        with:
58          name: SARIF file
59          path: results.sarif
60          retention-days: 5
61
62      - name: "Upload to code-scanning"
63        uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
64        with:
65          sarif_file: results.sarif