Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 24 additions & 6 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,22 +1,40 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Thin wrapper around hyperpolymath/standards scorecard-reusable.yml, in the
# shape of the standards caller (standards/.github/workflows/scorecard.yml).
# Deliberate differences from that caller: the cross-repo SHA pin, this repo's
# existing weekly cron, and the branch_protection_rule trigger. See #168.

name: Scorecards supply-chain security

on:
push:
branches: [main]
pull_request:
branch_protection_rule:
schedule:
- cron: '23 4 * * 1'
workflow_dispatch:

# Estate guardrail: cancel superseded runs so re-pushes don't pile up.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions: read-all
# A job-level `permissions:` block REPLACES the workflow-level map, so the
# calling job below must itself grant every scope the callee's jobs request:
# actions: read (Scorecard's Packaging check), contents: read (checkout),
# security-events: write (SARIF upload), id-token: write (OIDC publication).
# This file died at startup 20/20 times while the job block carried only
# security-events + id-token, which left actions and contents at `none` (#168).
permissions:
contents: read

jobs:
analysis:
scorecard:
permissions:
actions: read
contents: read
security-events: write
id-token: write
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4
secrets: inherit
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@0f13f51fafe9d2b670252aa2a18993223bffdece
Loading