summaryrefslogtreecommitdiffhomepage
path: root/.github/workflows/osv-scanner-pr.yml
blob: a2b3bee603a3f3e288198214e567381dba002b22 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
---
name: OSV-Scanner PR Scan

on:
  pull_request:
  workflow_dispatch:

permissions: {}

jobs:
  scan-pr:
    permissions:
      # Require writing security events to upload SARIF file to security tab
      security-events: write
      # Only need to read contents
      contents: read
      actions: read

    # yamllint disable rule:line-length
    uses: "google/osv-scanner-action/.github/workflows/osv-scanner-reusable-pr.yml@ab8175fc65a74d8c0308f623b1c617a39bdc34fe"  # v1.9.2 + submodule patch
    with:
      checkout-submodules: true