Skip to content

Bump fossas/fossa-action from 1.3.1 to 1.5.0 (#2109) #824

Bump fossas/fossa-action from 1.3.1 to 1.5.0 (#2109)

Bump fossas/fossa-action from 1.3.1 to 1.5.0 (#2109) #824

---
name: ossf-scorecard
on:
schedule:
- cron: '20 7 * * 2'
push:
branches:
- 'main'
permissions: read-all
jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-latest
permissions:
# Needed to publish result and generate a badge.
id-token: write
# Needed to upload the results to code-scanning dashboard.
security-events: write
contents: read
actions: read
steps:
- uses: actions/checkout@8f4b7f84864484a7bf31766abe9204da3cbe65b3 # v3.5.0
- uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3
with:
publish_results: true
results_file: results.sarif
results_format: sarif
- uses: github/codeql-action/upload-sarif@dd746615b3b9d728a6a37ca2045b68ca76d4841a # v3.28.8
with:
sarif_file: results.sarif