mirror of https://github.com/dexidp/dex.git
2 changed files with 48 additions and 0 deletions
@ -0,0 +1,47 @@
|
||||
name: OpenSSF Scorecard |
||||
|
||||
on: |
||||
branch_protection_rule: |
||||
push: |
||||
branches: [ main ] |
||||
schedule: |
||||
- cron: '30 0 * * 5' |
||||
|
||||
permissions: |
||||
contents: read |
||||
|
||||
jobs: |
||||
analyze: |
||||
name: Analyze |
||||
runs-on: ubuntu-latest |
||||
|
||||
permissions: |
||||
actions: read |
||||
contents: read |
||||
id-token: write |
||||
security-events: write |
||||
|
||||
steps: |
||||
- name: Checkout repository |
||||
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3.5.2 |
||||
with: |
||||
persist-credentials: false |
||||
|
||||
- name: Run analysis |
||||
uses: ossf/scorecard-action@80e868c13c90f172d68d1f4501dee99e2479f7af # v2.1.3 |
||||
with: |
||||
results_file: results.sarif |
||||
results_format: sarif |
||||
publish_results: true |
||||
|
||||
- name: Upload results as artifact |
||||
uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2 |
||||
with: |
||||
name: OpenSSF Scorecard results |
||||
path: results.sarif |
||||
retention-days: 5 |
||||
|
||||
- name: Upload results to GitHub Security tab |
||||
uses: github/codeql-action/upload-sarif@8662eabe0e9f338a07350b7fd050732745f93848 # v2.3.1 |
||||
with: |
||||
sarif_file: results.sarif |
||||
Loading…
Reference in new issue