File tree 2 files changed +17
-4
lines changed
2 files changed +17
-4
lines changed Original file line number Diff line number Diff line change
1
+ # See Dependabot documentation for all configuration options:
2
+ # https://help.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
3
+
4
+ version : 2
5
+ updates :
6
+ - package-ecosystem : " github-actions"
7
+ directory : " /"
8
+ schedule :
9
+ interval : " weekly"
10
+ labels :
11
+ - " autosubmit"
Original file line number Diff line number Diff line change @@ -18,15 +18,17 @@ jobs:
18
18
security-events : write
19
19
actions : read
20
20
contents : read
21
+ # Needed to access OIDC token.
22
+ id-token : write
21
23
22
24
steps :
23
25
- name : " Checkout code"
24
- uses : actions/checkout@a12a3943b4bdde767164f792f33f40b04645d846
26
+ uses : actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
25
27
with :
26
28
persist-credentials : false
27
29
28
30
- name : " Run analysis"
29
- uses : ossf/scorecard-action@c1aec4ac820532bab364f02a81873c555a0ba3a1
31
+ uses : ossf/scorecard-action@e363bfca00e752f91de7b7d2a77340e2e523cb18
30
32
with :
31
33
results_file : results.sarif
32
34
results_format : sarif
@@ -41,14 +43,14 @@ jobs:
41
43
42
44
# Upload the results as artifacts (optional).
43
45
- name : " Upload artifact"
44
- uses : actions/upload-artifact@6673cd052c4cd6fcf4b4e6e60ea986c889389535
46
+ uses : actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8
45
47
with :
46
48
name : SARIF file
47
49
path : results.sarif
48
50
retention-days : 5
49
51
50
52
# Upload the results to GitHub's code scanning dashboard.
51
53
- name : " Upload to code-scanning"
52
- uses : github/codeql-action/upload-sarif@883476649888a9e8e219d5b2e6b789dc024f690c
54
+ uses : github/codeql-action/upload-sarif@86f3159a697a097a813ad9bfa0002412d97690a4
53
55
with :
54
56
sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments