fossa.yml 600 B

12345678910111213141516171819202122232425
  1. name: FOSSA scanning
  2. on:
  3. push:
  4. branches:
  5. - main
  6. permissions:
  7. contents: read
  8. jobs:
  9. fossa:
  10. runs-on: ubuntu-latest
  11. steps:
  12. - name: Harden the runner (Audit all outbound calls)
  13. uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
  14. with:
  15. egress-policy: audit
  16. - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
  17. - uses: fossas/fossa-action@3ebcea1862c6ffbd5cf1b4d0bd6b3fe7bd6f2cac # v1.7.0
  18. with:
  19. api-key: ${{secrets.FOSSA_API_KEY}}
  20. team: OpenTelemetry