From 553ac01cff3fa51489f08089e2b2fe631f1e7539 Mon Sep 17 00:00:00 2001 From: Paolo Mainardi Date: Fri, 19 Jul 2024 19:05:17 +0200 Subject: [PATCH] feat: install scorecard --- .github/workflows/action.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/action.yml b/.github/workflows/action.yml index c5c692d..b4b07a2 100644 --- a/.github/workflows/action.yml +++ b/.github/workflows/action.yml @@ -19,6 +19,11 @@ jobs: sudo apt-get update sudo apt-get install -y jq curl + - name: Install scorecard + run: | + curl -sSL https://github.com/ossf/scorecard/releases/download/v4.13.1/scorecard_4.13.1_linux_amd64.tar.gz | tar xz -C /tmp && sudo mv /tmp/./scorecard-linux-amd64 /usr/local/bin/scorecard + chmod +x /usr/local/bin/scorecard + - name: Run evaluation script env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}