We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 6df9b1d commit 9fc6e51Copy full SHA for 9fc6e51
.github/workflows/ossf_scorecard.yml
@@ -15,6 +15,7 @@ jobs:
15
analysis:
16
name: Scorecard analysis
17
runs-on: ubuntu-latest
18
+ environment: scorecard
19
permissions:
20
security-events: write # update code-scanning dashboard
21
id-token: write # confirm org+repo identity before publish results
@@ -31,6 +32,7 @@ jobs:
31
32
results_file: results.sarif
33
results_format: sarif
34
publish_results: true # publish to OSSF Scorecard REST API
35
+ repo_token: ${{ secrets.SCORECARD_TOKEN }} # read-only fine-grained token to read branch protection settings
36
37
- name: "Upload results"
38
uses: actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce # v3.1.2
0 commit comments