File tree Expand file tree Collapse file tree 5 files changed +49
-4
lines changed Expand file tree Collapse file tree 5 files changed +49
-4
lines changed Original file line number Diff line number Diff line change 1414 persist-credentials : false
1515
1616 - name : " Dependency Review"
17- uses : actions/dependency-review-action@v4
17+ uses : actions/dependency-review-action@595b5aeba73380359d98a5e087f648dbb0edce1b # v4.7.3
Original file line number Diff line number Diff line change 1+ name : Scorecard supply-chain security
2+ on :
3+ branch_protection_rule :
4+ schedule :
5+ - cron : ' 27 12 * * 2'
6+ push :
7+ branches : [ "main" ]
8+
9+ permissions : read-all
10+
11+ jobs :
12+ analysis :
13+ name : Scorecard analysis
14+ runs-on : ubuntu-latest
15+ if : github.event.repository.default_branch == github.ref_name || github.event_name == 'pull_request'
16+ permissions :
17+ security-events : write
18+ id-token : write
19+
20+ steps :
21+ - name : " Checkout code"
22+ uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
23+ with :
24+ persist-credentials : false
25+
26+ - name : " Run analysis"
27+ uses : ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
28+ with :
29+ results_file : results.sarif
30+ results_format : sarif
31+ publish_results : true
32+
33+ - name : " Upload artifact"
34+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
35+ with :
36+ name : SARIF file
37+ path : results.sarif
38+ retention-days : 5
39+
40+ - name : " Upload to code-scanning"
41+ uses : github/codeql-action/upload-sarif@f1f6e5f6af878fb37288ce1c627459e94dbf7d01 # v3.30.1
42+ with :
43+ sarif_file : results.sarif
Original file line number Diff line number Diff line change 2727 run : zip -r ../html5-boilerplate_${{ steps.get_version.outputs.VERSION }}.zip ./
2828 - name : Create Release
2929 id : create_release
30- uses : actions/create-release@v1
30+ uses : actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e # v1.1.4
3131 env :
3232 GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
3333 with :
3737 prerelease : false
3838 - name : Upload Release Asset
3939 id : upload-release-asset
40- uses : actions/upload-release-asset@v1
40+ uses : actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5 # v1.0.2
4141 env :
4242 GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
4343 with :
Original file line number Diff line number Diff line change 2222 restore-keys : |
2323 ${{ runner.os }}-node-
2424 - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
25+ with :
26+ persist-credentials : false
2527 - name : Setup Node.js
2628 uses : actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
2729 with :
Original file line number Diff line number Diff line change 2626 id : npm-cache
2727 run : |
2828 echo "dir=$(npm config get cache)" >> "$GITHUB_OUTPUT"
29- - uses : actions/cache@v3
29+ - uses : actions/cache@2f8e54208210a422b2efd51efaa6bd6d7ca8920f # v3.4.3
3030 with :
3131 path : ${{ steps.npm-cache.outputs.dir }}
3232 key : ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
You can’t perform that action at this time.
0 commit comments