Skip to content

Merge pull request #376 from fish-shop/dependabot/github_actions/vers… #243

Merge pull request #376 from fish-shop/dependabot/github_actions/vers…

Merge pull request #376 from fish-shop/dependabot/github_actions/vers… #243

name: OpenSSF Scorecard Analysis
on:
branch_protection_rule:
schedule:
- cron: '0 3 * * 1'
push:
branches: [ "main" ]
permissions: read-all
jobs:
analysis:
name: OpenSSF Scorecard Analysis
permissions:
security-events: write # Needed to upload the results to code scanning dashboard
id-token: write # Needed to publish results to OpenSSF API and get a badge
uses: fish-shop/workflows/.github/workflows/openssf-scorecard.yml@ad1c3f75e07f5bcb5696ca61627274881b2f6502 # v1.13.46