Skip to content

Commit dd4c706

Browse files
authored
chore(ci): switch Scorecard action to common reusable one (#481)
1 parent 0354790 commit dd4c706

1 file changed

Lines changed: 7 additions & 22 deletions

File tree

.github/workflows/scorecard.yml

Lines changed: 7 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -7,30 +7,15 @@ on:
77
branches:
88
- main
99

10-
permissions:
11-
contents: read
10+
permissions: {}
1211

1312
jobs:
14-
analysis:
15-
name: Scorecard analysis
16-
runs-on: ubuntu-latest
13+
scorecard:
14+
name: Scorecard
1715
permissions:
16+
contents: read
1817
id-token: write
1918
security-events: write
20-
steps:
21-
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
22-
with:
23-
persist-credentials: false
24-
- uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
25-
with:
26-
results_file: results.sarif
27-
results_format: sarif
28-
publish_results: true
29-
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
30-
with:
31-
name: SARIF file
32-
path: results.sarif
33-
retention-days: 7
34-
- uses: github/codeql-action/upload-sarif@181d5eefc20863364f96762470ba6f862bdef56b # v3.29.2
35-
with:
36-
sarif_file: results.sarif
19+
uses: UpCloudLtd/workflows/.github/workflows/openssf-scorecard.yaml@main
20+
with:
21+
publish-results: true

0 commit comments

Comments
 (0)