Skip to content

Scorecard

Scorecard #2

Workflow file for this run

name: "Scorecard"
on:
branch_protection_rule:
schedule:
- cron: "0 0 * * 0"
push:
branches: ["main", "1.26.x"]
permissions: read-all
jobs:
analysis:
name: "Scorecard"
runs-on: "ubuntu-latest"
permissions:
security-events: write
id-token: write
contents: read
actions: read
steps:
- name: "Checkout repository"
uses: "actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b"
with:
persist-credentials: false
- name: "Run Scorecard"
uses: "ossf/scorecard-action@e38b1902ae4f44df626f11ba0734b14fb91f8f86"
with:
results_file: results.sarif
results_format: sarif
repo_token: ${{ secrets.SCORECARD_TOKEN }}
publish_results: true