File tree 1 file changed +4
-3
lines changed
1 file changed +4
-3
lines changed Original file line number Diff line number Diff line change 1
1
name : Scorecard supply-chain security
2
2
on :
3
+ workflow_dispatch :
3
4
# For Branch-Protection check. Only the default branch is supported. See
4
5
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
5
6
branch_protection_rule :
30
31
persist-credentials : false
31
32
32
33
- name : " Run analysis"
33
- uses : ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3 .1
34
+ uses : ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4 .1
34
35
with :
35
36
results_file : results.sarif
36
37
results_format : sarif
48
49
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
49
50
# format to the repository Actions tab.
50
51
- name : " Upload artifact"
51
- uses : actions/upload-artifact@97a0fba1372883ab732affbe8f94b823f91727db # v3.pre.node20
52
+ uses : actions/upload-artifact@4cec3d8aa04e39d1a68397de0c4cd6fb9dce8ec1 # v4.6.1
52
53
with :
53
54
name : SARIF file
54
55
path : results.sarif
57
58
# Upload the results to GitHub's code scanning dashboard (optional).
58
59
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
59
60
- name : " Upload to code-scanning"
60
- uses : github/codeql-action/upload-sarif@v3
61
+ uses : github/codeql-action/upload-sarif@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
61
62
with :
62
63
sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments