diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml deleted file mode 100644 index c28d71b..0000000 --- a/.github/workflows/scorecard.yml +++ /dev/null @@ -1,46 +0,0 @@ -name: scorecard supply-chain security - -on: - branch_protection_rule: - schedule: - - cron: '26 15 * * 3' - push: - branches: - - 'main' - -permissions: - contents: read - -jobs: - analysis: - name: Scorecard analysis - runs-on: ubuntu-latest - - permissions: - security-events: write - id-token: write - - steps: - - name: Checkout - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3 - with: - persist-credentials: false - - - name: Analyze - uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1 - with: - results_file: results.sarif - results_format: sarif - publish_results: true - - - name: Upload SARIF results - uses: actions/upload-artifact@97a0fba1372883ab732affbe8f94b823f91727db # v3.pre.node20 - with: - name: SARIF file - path: results.sarif - retention-days: 5 - - - name: Upload results to code scanning - uses: github/codeql-action/upload-sarif@c7f9125735019aa87cfc361530512d50ea439c71 # v3.25.1 - with: - sarif_file: results.sarif