File tree Expand file tree Collapse file tree 1 file changed +49
-0
lines changed Expand file tree Collapse file tree 1 file changed +49
-0
lines changed Original file line number Diff line number Diff line change 1+ name : Scorecards supply-chain security
2+ on :
3+ workflow_dispatch :
4+ schedule :
5+ # Weekly on Saturdays.
6+ - cron : " 30 1 * * 6"
7+ push :
8+ branches :
9+ - main
10+
11+ permissions :
12+ contents : read
13+ issues : read
14+ pull-requests : read
15+ checks : read
16+ actions : read
17+
18+ jobs :
19+ analysis :
20+ name : Scorecards analysis
21+ runs-on : ubuntu-latest
22+
23+ steps :
24+ - name : " Checkout code"
25+ uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
26+ with :
27+ persist-credentials : false
28+
29+ - name : " Run analysis"
30+ uses : ossf/scorecard-action@169c9b9248e36d400bebded8160c7fe2cbbc7762
31+ with :
32+ results_file : ossf-results.json
33+ results_format : json
34+ publish_results : false
35+
36+ - name : " Add metadata"
37+ run : |
38+ full_repo="${{ github.repository }}"
39+ OWNER=${full_repo%/*}
40+ REPO=${full_repo#*/}
41+ jq -c '. + {"metadata_owner": "'$OWNER'", "metadata_repo": "'$REPO'", "metadata_query": "ossf"}' ossf-results.json > ossf-results-modified.json
42+
43+ - name : " Post results to Sentinel"
44+ uses : cds-snc/sentinel-forward-data-action@01db4a9203054ecdb60ff368c3cdfca71d62e85f
45+ with :
46+ file_name : ossf-results-modified.json
47+ log_type : GitHubMetadata_OSSF_Scorecard
48+ log_analytics_workspace_id : ${{ secrets.LOG_ANALYTICS_WORKSPACE_ID }}
49+ log_analytics_workspace_key : ${{ secrets.LOG_ANALYTICS_WORKSPACE_KEY }}
You can’t perform that action at this time.
0 commit comments