Skip to content

✨ run-analysis action files - #1

Merged
laurentsimon merged 2 commits into
mainfrom
feat/run-analysis
Nov 8, 2021
Merged

laurentsimon merged 2 commits into
mainfrom
feat/run-analysis

Conversation

@laurentsimon

@laurentsimon laurentsimon commented Nov 5, 2021 •

Copy link
Copy Markdown
Contributor

Files to run the scorecard action.
See this file to see how to use it from a workflow https://github.com/laurentsimon/scorecard-action-test-4/blob/main/.github/workflows/scorecard-analysis.yml#L24
The branch is set to this PR branch for testing only - by default main branch is used and it not necessary.

@asraa asraa left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! LGTM

Assuming eventually you'd like a README in this repo (esp to define the policy, since there's no default one) -- happy to start a PR for this unless you have some copy-paste-able doc already ready!


if [[ "$GITHUB_EVENT_NAME" == "pull_request"* ]]
then
$SCORECARD_BIN --local . --format sarif --show-details --policy="$SCORECARD_POLICY_FILE" > "$SCORECARD_SARIF_FILE"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

just curious, will this depend on the repo being checked out? (i.e. use actions/checkout somewhere) -- maybe this is already done?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@laurentsimon

Copy link
Copy Markdown
Contributor Author

Thanks! LGTM

Assuming eventually you'd like a README in this repo (esp to define the policy, since there's no default one) -- happy to start a PR for this unless you have some copy-paste-able doc already ready!

Feel free to start it. I don't have it yet. I'm going to change the arguments it takes to be more generic this week.

@laurentsimon
laurentsimon merged commit abb0901 into main Nov 8, 2021
naveensrinivasan pushed a commit that referenced this pull request Jul 25, 2022
@naveensrinivasan

Copy link
Copy Markdown
Member

Scorecard Results


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants