mirror of https://github.com/dexidp/dex.git
2 changed files with 48 additions and 0 deletions
@ -0,0 +1,47 @@ |
|||||||
|
name: OpenSSF Scorecard |
||||||
|
|
||||||
|
on: |
||||||
|
branch_protection_rule: |
||||||
|
push: |
||||||
|
branches: [ main ] |
||||||
|
schedule: |
||||||
|
- cron: '30 0 * * 5' |
||||||
|
|
||||||
|
permissions: |
||||||
|
contents: read |
||||||
|
|
||||||
|
jobs: |
||||||
|
analyze: |
||||||
|
name: Analyze |
||||||
|
runs-on: ubuntu-latest |
||||||
|
|
||||||
|
permissions: |
||||||
|
actions: read |
||||||
|
contents: read |
||||||
|
id-token: write |
||||||
|
security-events: write |
||||||
|
|
||||||
|
steps: |
||||||
|
- name: Checkout repository |
||||||
|
uses: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab # v3.5.2 |
||||||
|
with: |
||||||
|
persist-credentials: false |
||||||
|
|
||||||
|
- name: Run analysis |
||||||
|
uses: ossf/scorecard-action@80e868c13c90f172d68d1f4501dee99e2479f7af # v2.1.3 |
||||||
|
with: |
||||||
|
results_file: results.sarif |
||||||
|
results_format: sarif |
||||||
|
publish_results: true |
||||||
|
|
||||||
|
- name: Upload results as artifact |
||||||
|
uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2 |
||||||
|
with: |
||||||
|
name: OpenSSF Scorecard results |
||||||
|
path: results.sarif |
||||||
|
retention-days: 5 |
||||||
|
|
||||||
|
- name: Upload results to GitHub Security tab |
||||||
|
uses: github/codeql-action/upload-sarif@8662eabe0e9f338a07350b7fd050732745f93848 # v2.3.1 |
||||||
|
with: |
||||||
|
sarif_file: results.sarif |
||||||
Loading…
Reference in new issue