✨ run-analysis action files - #1
Conversation
asraa
left a comment
There was a problem hiding this comment.
Thanks! LGTM
Assuming eventually you'd like a README in this repo (esp to define the policy, since there's no default one) -- happy to start a PR for this unless you have some copy-paste-able doc already ready!
|
|
||
| if [[ "$GITHUB_EVENT_NAME" == "pull_request"* ]] | ||
| then | ||
| $SCORECARD_BIN --local . --format sarif --show-details --policy="$SCORECARD_POLICY_FILE" > "$SCORECARD_SARIF_FILE" |
There was a problem hiding this comment.
just curious, will this depend on the repo being checked out? (i.e. use actions/checkout somewhere) -- maybe this is already done?
There was a problem hiding this comment.
Feel free to start it. I don't have it yet. I'm going to change the arguments it takes to be more generic this week. |
Scorecard Results
|
Files to run the scorecard action.
See this file to see how to use it from a workflow https://github.com/laurentsimon/scorecard-action-test-4/blob/main/.github/workflows/scorecard-analysis.yml#L24
The branch is set to this PR branch for testing only - by default main branch is used and it not necessary.