diff options
| author | Darius Jahandarie <djahandarie@gmail.com> | 2023-03-12 19:28:41 +0900 | 
|---|---|---|
| committer | GitHub <noreply@github.com> | 2023-03-12 19:28:41 +0900 | 
| commit | 0aa9d7ef99bbe99d68565c5921c1b3db59ce7f45 (patch) | |
| tree | 09d546f957287675c8318a45da20ad4efedafebc | |
| parent | 81cbb6c78779178bd7bbeeae3c4028ec6f34097a (diff) | |
| parent | bbb7ce03feb161994eeed0dcd1be08f167f27996 (diff) | |
Merge pull request #93 from themoeway/scorecard
Add OSSF scorecard action
| -rw-r--r-- | .github/workflows/scorecard.yml | 68 | 
1 files changed, 68 insertions, 0 deletions
| diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml new file mode 100644 index 00000000..c39c52bb --- /dev/null +++ b/.github/workflows/scorecard.yml @@ -0,0 +1,68 @@ +name: Scorecard supply-chain security +on: +  # For Branch-Protection check. Only the default branch is supported. See +  # https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection +  branch_protection_rule: +  # To guarantee Maintained check is occasionally updated. See +  # https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained +  schedule: +    - cron: "34 17 * * 1" +  push: +    branches: ["master"] + +# Declare default permissions as read only. +permissions: read-all + +jobs: +  analysis: +    name: Scorecard analysis +    runs-on: ubuntu-latest +    permissions: +      # Needed to upload the results to code-scanning dashboard. +      security-events: write +      # Needed to publish results and get a badge (see publish_results below). +      id-token: write +      # Uncomment the permissions below if installing in a private repository. +      # contents: read +      # actions: read + +    steps: +      - name: "Checkout code" +        uses: actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 # v3.1.0 +        with: +          persist-credentials: false + +      - name: "Run analysis" +        uses: ossf/scorecard-action@e38b1902ae4f44df626f11ba0734b14fb91f8f86 # v2.1.2 +        with: +          results_file: results.sarif +          results_format: sarif +          # (Optional) "write" PAT token. Uncomment the `repo_token` line below if: +          # - you want to enable the Branch-Protection check on a *public* repository, or +          # - you are installing Scorecard on a *private* repository +          # To create the PAT, follow the steps in https://github.com/ossf/scorecard-action#authentication-with-pat. +          # repo_token: ${{ secrets.SCORECARD_TOKEN }} + +          # Public repositories: +          #   - Publish results to OpenSSF REST API for easy access by consumers +          #   - Allows the repository to include the Scorecard badge. +          #   - See https://github.com/ossf/scorecard-action#publishing-results. +          # For private repositories: +          #   - `publish_results` will always be set to `false`, regardless +          #     of the value entered here. +          publish_results: true + +      # Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF +      # format to the repository Actions tab. +      - name: "Upload artifact" +        uses: actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8 # v3.1.0 +        with: +          name: SARIF file +          path: results.sarif +          retention-days: 5 + +      # Upload the results to GitHub's code scanning dashboard. +      - name: "Upload to code-scanning" +        uses: github/codeql-action/upload-sarif@17573ee1cc1b9d061760f3a006fc4aac4f944fd5 # v2.2.4 +        with: +          sarif_file: results.sarif |