Skip to content

Commit 246a512

Browse files
committed
Update scorecards and enable dependabot.
This is upgrading scorecards to the latest version and enables dependabot to autoupdate github actions. Bug: #6324
1 parent afc9c04 commit 246a512

File tree

2 files changed

+17
-4
lines changed

2 files changed

+17
-4
lines changed

.github/dependabot.yml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
# See Dependabot documentation for all configuration options:
2+
# https://help.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
3+
4+
version: 2
5+
updates:
6+
- package-ecosystem: "github-actions"
7+
directory: "/"
8+
schedule:
9+
interval: "weekly"
10+
labels:
11+
- "autosubmit"

.github/workflows/scorecards-analysis.yml

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,15 +18,17 @@ jobs:
1818
security-events: write
1919
actions: read
2020
contents: read
21+
# Needed to access OIDC token.
22+
id-token: write
2123

2224
steps:
2325
- name: "Checkout code"
24-
uses: actions/checkout@a12a3943b4bdde767164f792f33f40b04645d846
26+
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
2527
with:
2628
persist-credentials: false
2729

2830
- name: "Run analysis"
29-
uses: ossf/scorecard-action@c1aec4ac820532bab364f02a81873c555a0ba3a1
31+
uses: ossf/scorecard-action@e363bfca00e752f91de7b7d2a77340e2e523cb18
3032
with:
3133
results_file: results.sarif
3234
results_format: sarif
@@ -41,14 +43,14 @@ jobs:
4143

4244
# Upload the results as artifacts (optional).
4345
- name: "Upload artifact"
44-
uses: actions/upload-artifact@6673cd052c4cd6fcf4b4e6e60ea986c889389535
46+
uses: actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8
4547
with:
4648
name: SARIF file
4749
path: results.sarif
4850
retention-days: 5
4951

5052
# Upload the results to GitHub's code scanning dashboard.
5153
- name: "Upload to code-scanning"
52-
uses: github/codeql-action/upload-sarif@883476649888a9e8e219d5b2e6b789dc024f690c
54+
uses: github/codeql-action/upload-sarif@86f3159a697a097a813ad9bfa0002412d97690a4
5355
with:
5456
sarif_file: results.sarif

0 commit comments

Comments
 (0)