Skip to content

Add Scorecard workflow for supply-chain security analysis#762

Merged
BDonnot merged 2 commits into
dev_1.12.5from
BDonnot-patch-1
Jun 12, 2026
Merged

Add Scorecard workflow for supply-chain security analysis#762
BDonnot merged 2 commits into
dev_1.12.5from
BDonnot-patch-1

Conversation

@BDonnot

@BDonnot BDonnot commented Jun 3, 2026

Copy link
Copy Markdown
Collaborator

This workflow performs Scorecard analysis for supply-chain security, scheduled to run weekly and on pushes to the master branch.

This workflow performs Scorecard analysis for supply-chain security, scheduled to run weekly and on pushes to the master branch.

Signed-off-by: Benjamin DONNOT <BDonnot@users.noreply.github.com>
@codacy-production

codacy-production Bot commented Jun 3, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@sonarqubecloud

sonarqubecloud Bot commented Jun 3, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Comment thread .github/workflows/scorecard.yml Outdated
branches: [ "master" ]

# Declare default permissions as read only.
permissions: read-all
Signed-off-by: DONNOT Benjamin <benjamin.donnot@rte-france.com>
@BDonnot
BDonnot merged commit f83fc3a into dev_1.12.5 Jun 12, 2026
42 of 49 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants