Skip to content

Fix Scorecards publish permissions #4

Fix Scorecards publish permissions

Fix Scorecards publish permissions #4

Workflow file for this run

name: Scorecards
on:
push:
branches:
- master
- main
schedule:
- cron: "0 5 * * 1"
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
scorecards:
name: OSSF Scorecards
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- name: Analyze
uses: ossf/scorecard-action@v2.4.0
with:
results_file: scorecard-results.sarif
results_format: sarif
repo_token: ${{ secrets.GITHUB_TOKEN }}
publish_results: true