OSSF Scorecard #79
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| # This workflow is managed by gh actions-lock. | |
| name: OSSF Scorecard | |
| on: | |
| schedule: | |
| - cron: '0 4 * * *' | |
| workflow_dispatch: | |
| permissions: read-all | |
| # Estate policy (standards/docs/TRUSTED-BASE-REDUCTION-POLICY.adoc and the workflow | |
| # staleness check): OSSF Scorecard MUST NOT upload SARIF to GitHub Code Scanning unless | |
| # it runs for every PR head commit. This workflow runs on push-to-main and on a schedule, | |
| # NOT on pull_request — so Code Scanning would show findings that correspond to no PR | |
| # head commit, and PR checks would appear to carry security results they do not. | |
| # | |
| # Resolution: keep the scan, drop the Code Scanning upload. The SARIF is retained as a | |
| # build artifact instead, which is inspectable without polluting Code Scanning. | |
| jobs: | |
| analysis: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v6.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Run Scorecard | |
| uses: ossf/scorecard-action@v2.4.3 | |
| with: | |
| results_file: results.sarif | |
| results_format: sarif | |
| # NOT github/codeql-action/upload-sarif — see the policy note above. | |
| - name: Upload results as artifact | |
| uses: actions/upload-artifact@v4.3.0 | |
| with: | |
| name: scorecard-results | |
| path: results.sarif | |
| retention-days: 30 |