File tree Expand file tree Collapse file tree 5 files changed +49
-4
lines changed Expand file tree Collapse file tree 5 files changed +49
-4
lines changed Original file line number Diff line number Diff line change 1414          persist-credentials : false 
1515
1616      - name : " Dependency Review" 
17-         uses : actions/dependency-review-action@v4  
17+         uses : actions/dependency-review-action@595b5aeba73380359d98a5e087f648dbb0edce1b   #  v4.7.3 
Original file line number Diff line number Diff line change 1+ name : Scorecard supply-chain security 
2+ on :
3+   branch_protection_rule :
4+   schedule :
5+     - cron : ' 27 12 * * 2' 
6+   push :
7+     branches : [ "main" ] 
8+ 
9+ permissions : read-all 
10+ 
11+ jobs :
12+   analysis :
13+     name : Scorecard analysis 
14+     runs-on : ubuntu-latest 
15+     if : github.event.repository.default_branch == github.ref_name || github.event_name == 'pull_request' 
16+     permissions :
17+       security-events : write 
18+       id-token : write 
19+ 
20+     steps :
21+       - name : " Checkout code" 
22+         uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8  #  v5.0.0
23+         with :
24+           persist-credentials : false 
25+ 
26+       - name : " Run analysis" 
27+         uses : ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde  #  v2.4.2
28+         with :
29+           results_file : results.sarif 
30+           results_format : sarif 
31+           publish_results : true 
32+ 
33+       - name : " Upload artifact" 
34+         uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02  #  v4.6.2
35+         with :
36+           name : SARIF file 
37+           path : results.sarif 
38+           retention-days : 5 
39+ 
40+       - name : " Upload to code-scanning" 
41+         uses : github/codeql-action/upload-sarif@f1f6e5f6af878fb37288ce1c627459e94dbf7d01  #  v3.30.1
42+         with :
43+           sarif_file : results.sarif 
Original file line number Diff line number Diff line change 2727        run : zip -r ../html5-boilerplate_${{ steps.get_version.outputs.VERSION }}.zip ./ 
2828      - name : Create Release 
2929        id : create_release 
30-         uses : actions/create-release@v1  
30+         uses : actions/create-release@0cb9c9b65d5d1901c1f53e5e66eaf4afd303e70e   #  v1.1.4 
3131        env :
3232          GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
3333        with :
3737          prerelease : false 
3838      - name : Upload Release Asset 
3939        id : upload-release-asset 
40-         uses : actions/upload-release-asset@v1  
40+         uses : actions/upload-release-asset@e8f9f06c4b078e705bd2ea027f0926603fc9b4d5   #  v1.0.2 
4141        env :
4242          GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }} 
4343        with :
Original file line number Diff line number Diff line change 2222          restore-keys : | 
2323            ${{ runner.os }}-node- 
2424       - uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8  #  v5.0.0
25+         with :
26+           persist-credentials : false 
2527      - name : Setup Node.js 
2628        uses : actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444  #  v5.0.0
2729        with :
Original file line number Diff line number Diff line change 2626        id : npm-cache 
2727        run : | 
2828          echo "dir=$(npm config get cache)" >> "$GITHUB_OUTPUT" 
29-        - uses : actions/cache@v3  
29+        - uses : actions/cache@2f8e54208210a422b2efd51efaa6bd6d7ca8920f   #  v3.4.3 
3030        with :
3131          path : ${{ steps.npm-cache.outputs.dir }} 
3232          key : ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }} 
    
 
   
 
     
   
   
          
     
  
    
     
 
    
      
     
 
     
    You can’t perform that action at this time.
  
 
    
  
     
    
      
        
     
 
       
      
     
   
 
    
    
  
 
  
 
     
    
0 commit comments