File tree Expand file tree Collapse file tree 3 files changed +42
-3
lines changed Expand file tree Collapse file tree 3 files changed +42
-3
lines changed Original file line number Diff line number Diff line change 3636 with :
3737 languages : ${{ matrix.language }}
3838 - name : Set up JDK
39- uses : actions/setup-java@1df8dbefe2a8cbc99770194893dd902763bee34b # v3.9 .0
39+ uses : actions/setup-java@3f07048e3d294f56e9b90ac5ea2c6f74e9ad0f98 # v3.10 .0
4040 with :
4141 distribution : " temurin"
4242 java-version : 11
Original file line number Diff line number Diff line change 1+ # synced from @nextcloud/android-config
12name : " Validate Gradle Wrapper"
23on :
34 pull_request :
1314 name : " Validation"
1415 runs-on : ubuntu-latest
1516 steps :
16- - uses : actions/checkout@v3
17- - uses : gradle/wrapper-validation-action@v1
17+ - uses : actions/checkout@ac593985615ec2ede58e132d2e21d2b1cbd6127c # v3.3.0
18+ - uses : gradle/wrapper-validation-action@55e685c48d84285a5b0418cd094606e199cca3b6 # v1.0.5
Original file line number Diff line number Diff line change 1+ # synced from @nextcloud/android-config
2+ name : Scorecard supply-chain security
3+ on :
4+ branch_protection_rule :
5+ schedule :
6+ - cron : ' 32 23 * * 4'
7+ push :
8+ branches : [ "main", "master" ]
9+
10+ # Declare default permissions as read only.
11+ permissions : read-all
12+
13+ jobs :
14+ analysis :
15+ name : Scorecard analysis
16+ runs-on : ubuntu-latest
17+ permissions :
18+ # Needed to upload the results to code-scanning dashboard.
19+ security-events : write
20+
21+ steps :
22+ - name : " Checkout code"
23+ uses : actions/checkout@93ea575cb5d8a053eaa0ac8fa3b40d7e05a33cc8 # v3.1.0
24+ with :
25+ persist-credentials : false
26+
27+ - name : " Run analysis"
28+ uses : ossf/scorecard-action@99c53751e09b9529366343771cc321ec74e9bd3d # v2.0.6
29+ with :
30+ results_file : results.sarif
31+ results_format : sarif
32+ publish_results : false
33+
34+ # Upload the results to GitHub's code scanning dashboard.
35+ - name : " Upload to code-scanning"
36+ uses : github/codeql-action/upload-sarif@807578363a7869ca324a79039e6db9c843e0e100 # v2.1.27
37+ with :
38+ sarif_file : results.sarif
You can’t perform that action at this time.
0 commit comments