diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml new file mode 100644 index 0000000..6ca0bf8 --- /dev/null +++ b/.github/workflows/scorecard.yml @@ -0,0 +1,56 @@ +name: Scorecard + +# OpenSSF Scorecard grades the things a reader cannot check by reading the code: +# whether releases are signed, whether actions are pinned, whether a dangerous +# workflow trigger is in use, how quickly dependencies are patched. It is the +# one measure of this repository that is produced by somebody else, which is +# most of its value -- every other badge here is generated by this project's own +# CI, and a project grading its own supply chain is the assertion this +# organisation says it does not accept. +# +# The score is published so the badge resolves, and the findings land in the +# repository's code scanning dashboard beside CodeQL's. +on: + push: + branches: [master] # the default branch is the only one Scorecard supports + schedule: + - cron: "30 1 * * 6" # weekly, Saturday 01:30 UTC + workflow_dispatch: + +permissions: read-all + +jobs: + analysis: + name: Scorecard analysis + runs-on: ubuntu-latest + permissions: + security-events: write # upload the SARIF to code scanning + id-token: write # OIDC token, so the published result is attributable + + steps: + # Actions in this workflow are pinned by commit, not by tag: Scorecard's + # own Pinned-Dependencies check is the reason, and a workflow that grades + # supply chains should not be the one taking a moving tag on trust. + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Run analysis + uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 + with: + results_file: results.sarif + results_format: sarif + publish_results: true + + - name: Upload the SARIF as an artifact + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: scorecard-sarif + path: results.sarif + retention-days: 5 + + - name: Upload to code scanning + uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 + with: + sarif_file: results.sarif diff --git a/README.md b/README.md index 11d6c95..20b308c 100644 --- a/README.md +++ b/README.md @@ -7,6 +7,7 @@ [![CI](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml) [![CodeQL](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml) [![Coverage](https://codecov.io/gh/DrobyshevDev/mlango/branch/master/graph/badge.svg)](https://codecov.io/gh/DrobyshevDev/mlango) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/DrobyshevDev/mlango/badge)](https://scorecard.dev/viewer/?uri=github.com/DrobyshevDev/mlango) [![PyPI](https://img.shields.io/pypi/v/mlango)](https://pypi.org/project/mlango/) [![Python](https://img.shields.io/pypi/pyversions/mlango)](https://pypi.org/project/mlango/) [![License](https://img.shields.io/pypi/l/mlango)](https://opensource.org/licenses/MIT) diff --git a/README.ru.md b/README.ru.md index 228f7e1..2dd936c 100644 --- a/README.ru.md +++ b/README.ru.md @@ -7,6 +7,7 @@ [![CI](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/ci.yml) [![CodeQL](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml/badge.svg)](https://github.com/DrobyshevDev/mlango/actions/workflows/codeql.yml) [![Coverage](https://codecov.io/gh/DrobyshevDev/mlango/branch/master/graph/badge.svg)](https://codecov.io/gh/DrobyshevDev/mlango) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/DrobyshevDev/mlango/badge)](https://scorecard.dev/viewer/?uri=github.com/DrobyshevDev/mlango) [![PyPI](https://img.shields.io/pypi/v/mlango)](https://pypi.org/project/mlango/) [![Python](https://img.shields.io/pypi/pyversions/mlango)](https://pypi.org/project/mlango/) [![License](https://img.shields.io/pypi/l/mlango)](https://opensource.org/licenses/MIT)