blob: db742fb0f740bf317a1ab8aa266c7afd3ea7218a [file] [log] [blame]
name: OSSF Scorecard Weekly
on:
schedule:
- cron: '0 0 * * 0' # Runs every Sunday at midnight UTC
workflow_dispatch:
permissions:
contents: read
jobs:
ossf-scorecard:
# To write a badge
permissions:
id-token: write
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- name: Run analysis
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
publish_results: true
results_file: ossf_scorecard.json
results_format: json