Skip to content

fix(ci): pin third-party actions to full commit SHAs (#13) #39

fix(ci): pin third-party actions to full commit SHAs (#13)

fix(ci): pin third-party actions to full commit SHAs (#13) #39

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0
name: OSSF Scorecard
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
schedule:
- cron: '0 4 * * *'
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
actions: read
contents: read
jobs:
scorecard:
permissions:
contents: read
security-events: write
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@210f14e753c80064ec1bcae72f1d654dd9b0e687

Check failure on line 26 in .github/workflows/scorecard.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/scorecard.yml

Invalid workflow file

error parsing called workflow ".github/workflows/scorecard.yml" -> "hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@210f14e753c80064ec1bcae72f1d654dd9b0e687" : Invalid dependency lockfile "hyperpolymath/standards/.github/workflows/actions.lock@210f14e753c80064ec1bcae72f1d654dd9b0e687": workflow ".github/workflows/scorecard-reusable.yml" references actions not present in the lockfile: github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63 Run 'gh actions-lock' to regenerate the lockfile.
secrets: inherit