Skip to content

OSPS Security Assessment #11

OSPS Security Assessment

OSPS Security Assessment #11

Workflow file for this run

name: OSPS Security Assessment
on:
schedule:
- cron: "0 9 * * 1" # Weekly on Mondays at 9 AM UTC
workflow_dispatch: # Allow manual triggering
jobs:
osps-assessment:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # Required for SARIF upload
steps:
- name: Checkout repository
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- name: Open Source Project Security Baseline Scanner
uses: revanite-io/osps-baseline-action@ffcef1f33b6ee5b916c7e357e4ae1481b99b46b6 # v1.0.0
with:
owner: ${{ github.repository_owner }}
repo: ${{ github.event.repository.name }}
token: ${{ secrets.GH_AUTH_TOKEN }}
catalog: "osps-baseline"
upload-sarif: "true"
- name: Upload assessment results
if: always()
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
with:
name: osps-assessment-results-${{ github.run_number }}
path: evaluation_results/
retention-days: 30