Repository navigation
fix(fleet): restore safe fixer and gate reproducible proof-stack builds #1080
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| name: Scorecards supply-chain security | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| branch_protection_rule: | |
| schedule: | |
| - cron: '23 4 * * 1' | |
| permissions: | |
| contents: read | |
| jobs: | |
| analysis: | |
| if: github.event_name != 'pull_request' | |
| name: Publish default-branch Scorecard | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 15 | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| id-token: write | |
| # These are the publishing steps from standards at 571cc734. Keep them | |
| # local so every action is covered by this workflow's runtime lockfile. | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Analyze and publish default-branch Scorecard | |
| uses: ossf/scorecard-action@v2.4.4 | |
| with: | |
| results_file: results.sarif | |
| results_format: sarif | |
| publish_results: true | |
| - name: Upload Scorecard SARIF | |
| uses: github/codeql-action/upload-sarif@v4.37.8 | |
| with: | |
| sarif_file: results.sarif | |
| - name: Retain scan evidence | |
| uses: actions/upload-artifact@v7.0.1 | |
| with: | |
| name: scorecard-results | |
| path: results.sarif | |
| if-no-files-found: error | |
| retention-days: 90 | |
| pull-request-analysis: | |
| name: Scorecard PR analysis | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 15 | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # The publisher targets the default branch. PRs need their own | |
| # real SARIF analysis without OIDC or publishing to the public badge API. | |
| # OpenSSF currently labels its pull_request trigger experimental. | |
| - name: Analyze the pull request with OpenSSF Scorecard | |
| uses: ossf/scorecard-action@v2.4.4 | |
| with: | |
| results_file: results.sarif | |
| results_format: sarif | |
| publish_results: false | |
| - name: Upload Scorecard SARIF | |
| uses: github/codeql-action/upload-sarif@v4.37.8 | |
| with: | |
| sarif_file: results.sarif | |
| - name: Retain scan evidence | |
| uses: actions/upload-artifact@v7.0.1 | |
| with: | |
| name: scorecard-pr-results | |
| path: results.sarif | |
| if-no-files-found: error | |
| retention-days: 14 |