From d6d089d4d68eb04bcbcc6095855dc6583fba2b7b Mon Sep 17 00:00:00 2001 From: OpenTelemetry Bot <107717825+opentelemetrybot@users.noreply.github.com> Date: Tue, 25 Aug 2026 06:48:53 -0700 Subject: [PATCH] ci: migrate OSSF Scorecard to shared workflow --- .github/workflows/ossf-scorecard.yml | 45 +++++----------------------- 1 file changed, 7 insertions(+), 38 deletions(-) diff --git a/.github/workflows/ossf-scorecard.yml b/.github/workflows/ossf-scorecard.yml index 372ddc6a2..99d6eb1bc 100644 --- a/.github/workflows/ossf-scorecard.yml +++ b/.github/workflows/ossf-scorecard.yml @@ -8,45 +8,14 @@ on: - cron: "56 23 * * 6" # once a week workflow_dispatch: -permissions: read-all +permissions: {} jobs: analysis: - runs-on: ubuntu-latest permissions: - # Needed for Code scanning upload - security-events: write - # Needed for GitHub OIDC token if publish_results is true - id-token: write - steps: - - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 - with: - egress-policy: audit - - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 - with: - results_file: results.sarif - results_format: sarif - publish_results: true - - # Upload the results as artifacts (optional). Commenting out will disable - # uploads of run results in SARIF format to the repository Actions tab. - # https://docs.github.com/en/actions/advanced-guides/storing-workflow-data-as-artifacts - - name: "Upload artifact" - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 - with: - name: SARIF file - path: results.sarif - retention-days: 5 - - # Upload the results to GitHub's code scanning dashboard (optional). - # Commenting out will disable upload of results to your repo's Code Scanning dashboard - - name: "Upload to code-scanning" - uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7 - with: - sarif_file: results.sarif + contents: read # for actions/checkout + id-token: write # for Scorecard to publish results + security-events: write # for the SARIF upload to code scanning + uses: open-telemetry/shared-workflows/.github/workflows/scorecard.yml@dde3047a8f219c296772c17936b9d02bb7447af5 # v0.12.0 + with: + use-harden-runner: true