Refuse Defender exclusions for script interpreters, pin ps2exe (#100) #109
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: OpenSSF Scorecard | |
| # Runs the OpenSSF Scorecard checks against the repo and uploads the results | |
| # to GitHub's code-scanning dashboard. The badge in README is generated from | |
| # https://api.securityscorecards.dev — Scorecard publishes results to its | |
| # public registry when this workflow runs on the default branch. | |
| on: | |
| # Weekly run keeps the score fresh. | |
| schedule: | |
| - cron: '0 5 * * 1' | |
| push: | |
| branches: [master] | |
| workflow_dispatch: | |
| permissions: read-all | |
| jobs: | |
| analysis: | |
| name: Scorecard analysis | |
| # Scorecard's action is published for ubuntu-latest only. This job | |
| # analyzes the repo (not the PowerShell code) so the OS doesn't matter. | |
| runs-on: ubuntu-latest | |
| permissions: | |
| # Required for uploading results to code-scanning dashboard. | |
| security-events: write | |
| # Required to read repository state. | |
| id-token: write | |
| contents: read | |
| actions: read | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Run analysis | |
| uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 | |
| with: | |
| results_file: results.sarif | |
| results_format: sarif | |
| # publish_results: write to the public Scorecard registry so the | |
| # badge URL resolves. Requires a public repo, which RackStack is. | |
| publish_results: true | |
| - name: Upload artifact | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: SARIF file | |
| path: results.sarif | |
| retention-days: 5 | |
| - name: Upload to code-scanning | |
| uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6 | |
| with: | |
| sarif_file: results.sarif |