matrix-art

An image gallery for Matrix
git clone git://archive.git.mtrnord.blog/MTRNord/matrix-art.git
Log | Files | Refs | README | LICENSE

scorecards-analysis.yml (1899B)


      1 name: Scorecards supply-chain security
      2 on:
      3   # Only the default branch is supported.
      4   branch_protection_rule:
      5   schedule:
      6     - cron: "15 7 * * 0"
      7   push:
      8     branches: [main]
      9 
     10 # Declare default permissions as read only.
     11 permissions: read-all
     12 
     13 jobs:
     14   analysis:
     15     name: Scorecards analysis
     16     runs-on: self-hosted
     17     permissions:
     18       # Needed to upload the results to code-scanning dashboard.
     19       security-events: write
     20       actions: read
     21       contents: read
     22 
     23     steps:
     24       - name: "Checkout code"
     25         uses: actions/checkout@ec3a7ce113134d7a93b817d10a8272cb61118579 # v2.4.0
     26         with:
     27           persist-credentials: false
     28 
     29       - name: "Run analysis"
     30         uses: ossf/scorecard-action@c1aec4ac820532bab364f02a81873c555a0ba3a1 # v1.0.1
     31         with:
     32           results_file: results.sarif
     33           results_format: sarif
     34           # Read-only PAT token. To create it,
     35           # follow the steps in https://github.com/ossf/scorecard-action#pat-token-creation.
     36           repo_token: ${{ secrets.SCORECARD_READ_TOKEN }}
     37           # Publish the results to enable scorecard badges. For more details, see
     38           # https://github.com/ossf/scorecard-action#publishing-results.
     39           # For private repositories, `publish_results` will automatically be set to `false`,
     40           # regardless of the value entered here.
     41           publish_results: true
     42 
     43       # Upload the results as artifacts (optional).
     44       - name: "Upload artifact"
     45         uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v2.3.1
     46         with:
     47           name: SARIF file
     48           path: results.sarif
     49           retention-days: 5
     50 
     51       # Upload the results to GitHub's code scanning dashboard.
     52       - name: "Upload to code-scanning"
     53         uses: github/codeql-action/upload-sarif@a34ca99b4610d924e04c68db79e503e1f79f9f02 # v1.0.26
     54         with:
     55           sarif_file: results.sarif