Skip to content

Commit c2656ee

Browse files
Updated scorecard with the v2 beta (#340)
Signed-off-by: Naveen <[email protected]>
1 parent 37c0f75 commit c2656ee

File tree

1 file changed

+7
-9
lines changed

1 file changed

+7
-9
lines changed

.github/workflows/scorecards-analysis.yml

+7-9
Original file line numberDiff line numberDiff line change
@@ -29,19 +29,17 @@ jobs:
2929
persist-credentials: false
3030

3131
- name: "Run analysis"
32-
uses: ossf/scorecard-action@ce330fde6b1a5c9c75b417e7efc510b822a35564 # v1.0.1
32+
uses: ossf/scorecard-action@08dd0cebb088ac0fd6364339b1b3b68b75041ea8 # v2.0.0-alpha.2
3333
with:
3434
results_file: results.sarif
3535
results_format: sarif
36-
# Read-only PAT token. To create it,
37-
# follow the steps in https://github.com/ossf/scorecard-action#pat-token-creation.
38-
repo_token: ${{ secrets.SCORECARD_READ_TOKEN }}
39-
# Publish the results to enable scorecard badges. For more details, see
40-
# https://github.com/ossf/scorecard-action#publishing-results.
41-
# For private repositories, `publish_results` will automatically be set to `false`,
42-
# regardless of the value entered here.
36+
repo_token: ${{ secrets.GITHUB_TOKEN }}
37+
# Publish the results for public repositories to enable scorecard badges. For more details, see
38+
# https://github.com/ossf/scorecard-action#publishing-results.
39+
# For private repositories, `publish_results` will automatically be set to `false`, regardless
40+
# of the value entered here.
4341
publish_results: true
44-
42+
4543
# Upload the results as artifacts (optional).
4644
- name: "Upload artifact"
4745
uses: actions/upload-artifact@3cea5372237819ed00197afe530f5a7ea3e805c8 # v2.3.1

0 commit comments

Comments
 (0)