fix(security): resolve GitHub Actions workflow validation errors
- Remove invalid 'queries' input from CodeQL analyze action - Fix OSSF Scorecard action input parameter names - Use correct underscore naming for required inputs
This commit is contained in:
6
.github/workflows/security-scanning.yml
vendored
6
.github/workflows/security-scanning.yml
vendored
@@ -95,8 +95,6 @@ jobs:
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@v3
|
||||
with:
|
||||
queries: security-extended,security-and-quality
|
||||
|
||||
dependency-security-scan:
|
||||
name: Dependency Security Scan
|
||||
@@ -180,8 +178,8 @@ jobs:
|
||||
- name: Run OSSF Scorecard
|
||||
uses: ossf/scorecard-action@v2.3.3
|
||||
with:
|
||||
results-file: results.sarif
|
||||
results-format: sarif
|
||||
results_file: results.sarif
|
||||
results_format: sarif
|
||||
|
||||
- name: Upload OSSF Scorecard results to GitHub Security tab
|
||||
uses: github/codeql-action/upload-sarif@v3
|
||||
|
||||
Reference in New Issue
Block a user