Skip to content

ci: bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#149) #62

ci: bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#149)

ci: bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#149) #62

Workflow file for this run

# SPDX-FileCopyrightText: 2025-2026 CLARVIA ASBL, Luxembourg
# SPDX-License-Identifier: EUPL-1.2
name: OpenSSF Scorecard
on:
push:
branches: [main]
schedule:
# Run weekly on Sundays at 06:30 UTC
- cron: "30 6 * * 0"
workflow_dispatch:
permissions: read-all
jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-latest
permissions:
security-events: write # Upload SARIF results
id-token: write # Publish to OpenSSF API
steps:
- name: Checkout code
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Run OpenSSF Scorecard
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: results.sarif
results_format: sarif
publish_results: true
- name: Upload SARIF artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: SARIF file
path: results.sarif
retention-days: 5
- name: Upload to code-scanning
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
with:
sarif_file: results.sarif