Skip to content

Scorecards supply-chain security #137

Scorecards supply-chain security

Scorecards supply-chain security #137

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0
name: Scorecards supply-chain security
on:
branch_protection_rule:
schedule:
- cron: '23 4 * * 1'
# The reusable's scorecard job declares security-events:write + id-token:write;
# a called workflow's job permissions must be a SUBSET of the caller's grant
# (callee ⊆ caller) — `read-all` grants no writes, so the run startup-failed at
# plan time with zero jobs.
permissions:
actions: read
contents: read
security-events: write
id-token: write
jobs:
analysis:
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329

Check failure on line 21 in .github/workflows/scorecard.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/scorecard.yml

Invalid workflow file

error parsing called workflow ".github/workflows/scorecard.yml" -> "hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329" : workflow was not found. See https://docs.github.com/actions/learn-github-actions/reusing-workflows#access-to-reusable-workflows for more information.
secrets: inherit