Skip to content

Commit bccf047

Browse files
committed
ci: Add OpenSSF Scorecard analysis
Run OpenSSF Scorecard on pushes to master, branch protection changes and a weekly schedule, and upload its SARIF results to code scanning. It reports supply-chain posture this repository cares about: pinned actions, token permissions, branch protection and signed releases. Actions are pinned to full commit SHAs, as in the existing workflows. Permissions are read-only except the job's security-events (SARIF upload) and id-token (publishing results to the public Scorecard API). Scorecard runs only on the default branch, so this takes effect once reviewability-v1 is merged into master. Claude-Session: https://claude.ai/code/session_013gZvwvuocM7a7Ut4kiBFHw
1 parent e5b957a commit bccf047

1 file changed

Lines changed: 37 additions & 0 deletions

File tree

‎.github/workflows/scorecard.yml‎

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
name: Scorecard supply-chain security
2+
3+
on:
4+
branch_protection_rule:
5+
schedule:
6+
- cron: "29 4 * * 1"
7+
push:
8+
branches: [master]
9+
10+
permissions:
11+
contents: read
12+
13+
jobs:
14+
analysis:
15+
name: Scorecard analysis
16+
runs-on: ubuntu-latest
17+
permissions:
18+
contents: read
19+
security-events: write
20+
id-token: write
21+
steps:
22+
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
23+
with:
24+
persist-credentials: false
25+
- uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4
26+
with:
27+
results_file: results.sarif
28+
results_format: sarif
29+
publish_results: true
30+
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
31+
with:
32+
name: SARIF file
33+
path: results.sarif
34+
retention-days: 5
35+
- uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
36+
with:
37+
sarif_file: results.sarif

0 commit comments

Comments
 (0)