Skip to content

Commit e1a9ae8

Browse files
godofredocdnfield
authored andcommitted
Remove schedule runs of scorecards. (#38)
This will also add dependabot to auto update the workflows dependencies. Bug: flutter/flutter#99185
1 parent 0dae5ad commit e1a9ae8

File tree

2 files changed

+20
-6
lines changed

2 files changed

+20
-6
lines changed

impeller/.github/dependabot.yml

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
# See Dependabot documentation for all configuration options:
2+
# https://help.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
3+
4+
version: 2
5+
updates:
6+
- package-ecosystem: "github-actions"
7+
directory: "/"
8+
schedule:
9+
interval: "daily"
10+
reviewers:
11+
- "hixie"
12+
- "godofredoc"
13+
labels:
14+
- "team"
15+
- "team: infra"
16+
- "waiting for tree to go green"

impeller/.github/workflows/scorecards-analysis.yml

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,6 @@ name: Scorecards supply-chain security
22
on:
33
# Only the default branch is supported.
44
branch_protection_rule:
5-
schedule:
6-
- cron: '37 18 * * 2'
75
push:
86
branches: [ main ]
97

@@ -22,12 +20,12 @@ jobs:
2220

2321
steps:
2422
- name: "Checkout code"
25-
uses: actions/checkout@ec3a7ce113134d7a93b817d10a8272cb61118579 # v2.4.0
23+
uses: actions/checkout@ec3a7ce113134d7a93b817d10a8272cb61118579
2624
with:
2725
persist-credentials: false
2826

2927
- name: "Run analysis"
30-
uses: ossf/scorecard-action@b614d455ee90608b5e36e3299cd50d457eb37d5f # v1.0.3
28+
uses: ossf/scorecard-action@b614d455ee90608b5e36e3299cd50d457eb37d5f
3129
with:
3230
results_file: results.sarif
3331
results_format: sarif
@@ -42,14 +40,14 @@ jobs:
4240

4341
# Upload the results as artifacts (optional).
4442
- name: "Upload artifact"
45-
uses: actions/upload-artifact@82c141cc518b40d92cc801eee768e7aafc9c2fa2 # v2.3.1
43+
uses: actions/upload-artifact@82c141cc518b40d92cc801eee768e7aafc9c2fa2
4644
with:
4745
name: SARIF file
4846
path: results.sarif
4947
retention-days: 5
5048

5149
# Upload the results to GitHub's code scanning dashboard.
5250
- name: "Upload to code-scanning"
53-
uses: github/codeql-action/upload-sarif@5f532563584d71fdef14ee64d17bafb34f751ce5 # v1.0.26
51+
uses: github/codeql-action/upload-sarif@5f532563584d71fdef14ee64d17bafb34f751ce5
5452
with:
5553
sarif_file: results.sarif

0 commit comments

Comments
 (0)