Skip to content

Commit cfdcd40

Browse files
authored
Merge pull request #863 from Nordix/fix_openssf_wf
Fix openssf github action workflow
2 parents 7ce72e0 + 5813b47 commit cfdcd40

File tree

1 file changed

+6
-5
lines changed

1 file changed

+6
-5
lines changed

.github/workflows/openssf_scorecard.yaml

+6-5
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@ on:
99
push:
1010
branches:
1111
- main
12+
workflow_dispatch:
1213

1314
concurrency:
1415
group: ${{ github.workflow }}-${{ github.ref }}
@@ -22,24 +23,24 @@ jobs:
2223
id-token: write
2324
steps:
2425
- name: Checkout
25-
uses: actions/checkout@44c2b7a8a4ea60a981eaca3cf939b5f4305c123b # v4.1.5
26+
uses: actions/checkout@v4.2.2
2627
with:
2728
persist-credentials: false
2829
- name: Run analysis
29-
uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3
30+
uses: ossf/scorecard-action@v2.4.0
3031
with:
3132
results_file: results.sarif
3233
results_format: sarif
33-
# repo_token: ${{ secrets.SCORECARD_READ_TOKEN }}
3434
publish_results: true
3535
- name: Upload artifact
36-
uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
36+
uses: actions/upload-artifact@v4.6.0
3737
with:
3838
name: SARIF file
3939
path: results.sarif
4040
retention-days: 5
4141
- name: Upload to code-scanning
42-
uses: github/codeql-action/upload-sarif@cdcdbb579706841c47f7063dda365e292e5cad7a # v2.13.4
42+
uses: github/codeql-action/upload-sarif@v3.28.9
4343
with:
4444
sarif_file: results.sarif
45+
token: ${{ secrets.GITHUB_TOKEN }}
4546

0 commit comments

Comments
 (0)