From 4590e07e7dec3be714155f5614a35467647f7207 Mon Sep 17 00:00:00 2001 From: godofredoc Date: Tue, 13 Sep 2022 08:58:05 -0700 Subject: [PATCH] Manual update of scorecards 2.0.3 (#111441) --- .github/workflows/scorecards-analysis.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/scorecards-analysis.yml b/.github/workflows/scorecards-analysis.yml index 0631efa987f..6e9977af561 100644 --- a/.github/workflows/scorecards-analysis.yml +++ b/.github/workflows/scorecards-analysis.yml @@ -18,6 +18,8 @@ jobs: security-events: write actions: read contents: read + # Needed to access OIDC token. + id-token: write steps: - name: "Checkout code" @@ -26,7 +28,7 @@ jobs: persist-credentials: false - name: "Run analysis" - uses: ossf/scorecard-action@68bf5b3327e4fd443d2add8ab122280547b4a16d + uses: ossf/scorecard-action@865b4092859256271290c77adbd10a43f4779972 with: results_file: results.sarif results_format: sarif