docs: add Signed commits section to CONTRIBUTING (#98) #33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| name: Scorecard | |
| on: | |
| schedule: | |
| - cron: '0 0 * * 0' | |
| push: | |
| branches: [main, master] | |
| workflow_dispatch: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| actions: read # required by the reusable workflow (staleness check reads workflow runs) | |
| contents: read | |
| jobs: | |
| scorecard: | |
| uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540 | |
| # Reusable called-workflow permissions are CAPPED by the caller's grants; | |
| # without security-events: write here the scorecard SARIF upload fails with | |
| # startup_failure (hypatia WF018). id-token: write enables OIDC publish. | |
| # The reusable's job self-gates on non-pull_request events, so only | |
| # default-branch publication receives OIDC. | |
| permissions: | |
| contents: read | |
| security-events: write | |
| id-token: write |