--- # vi: ts=2 sw=2 et: # SPDX-License-Identifier: LGPL-2.1-or-later name: Scorecards supply-chain security on: # Only the default branch is supported. branch_protection_rule: schedule: - cron: '15 21 * * 6' push: branches: - main pull_request: branches: - main paths: - '.github/workflows/scorecards.yml' # Declare default permissions as read only. permissions: read-all jobs: analysis: name: Scorecards analysis if: github.repository == 'systemd/systemd' runs-on: ubuntu-latest permissions: id-token: write # Used to receive a badge. steps: - name: Checkout code uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 with: persist-credentials: false - name: Run analysis uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1 with: results_file: results.sarif results_format: sarif publish_results: ${{ github.event_name != 'pull_request' }}