File tree Expand file tree Collapse file tree 7 files changed +30
-18
lines changed Expand file tree Collapse file tree 7 files changed +30
-18
lines changed Original file line number Diff line number Diff line change 2222 contents : read
2323 security-events : write
2424 id-token : write
25- uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
25+ uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2626 with :
2727 run_version_check : false
2828 run_build : true
3333 project_folder : " attestation-manager"
3434 secrets :
3535 SYS_ORCH_GITHUB : ${{ secrets.SYS_ORCH_GITHUB }}
36- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
37- COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
3836 NO_AUTH_ECR_PUSH_USERNAME : ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3937 NO_AUTH_ECR_PUSH_PASSWD : ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
4038 MSTEAMS_WEBHOOK : ${{ secrets.TEAMS_WEBHOOK }}
Original file line number Diff line number Diff line change 2121 contents : read
2222 security-events : write
2323 id-token : write
24- uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+ uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525 with :
2626 run_version_check : false
2727 run_build : true
3232 project_folder : " attestation-verifier"
3333 secrets :
3434 SYS_ORCH_GITHUB : ${{ secrets.SYS_ORCH_GITHUB }}
35- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
36- COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
3735 NO_AUTH_ECR_PUSH_USERNAME : ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3836 NO_AUTH_ECR_PUSH_PASSWD : ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3937 MSTEAMS_WEBHOOK : ${{ secrets.TEAMS_WEBHOOK }}
Original file line number Diff line number Diff line change 2222 contents : read
2323 security-events : write
2424 id-token : write
25- uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
25+ uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2626 with :
2727 run_version_check : false
2828 run_build : true
3434 project_folder : " baremetal"
3535 secrets :
3636 SYS_ORCH_GITHUB : ${{ secrets.SYS_ORCH_GITHUB }}
37- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
38- COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
3937 NO_AUTH_ECR_PUSH_USERNAME : ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
4038 NO_AUTH_ECR_PUSH_PASSWD : ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
4139 MSTEAMS_WEBHOOK : ${{ secrets.TEAMS_WEBHOOK }}
Original file line number Diff line number Diff line change 2121 contents : read
2222 security-events : write
2323 id-token : write
24- uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+ uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525 with :
2626 run_build : false
2727 run_helm_build : true
3131 project_folder : " helm"
3232 secrets :
3333 SYS_ORCH_GITHUB : ${{ secrets.SYS_ORCH_GITHUB }}
34- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
35- COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
3634 NO_AUTH_ECR_PUSH_USERNAME : ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3735 NO_AUTH_ECR_PUSH_PASSWD : ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3836 MSTEAMS_WEBHOOK : ${{ secrets.TEAMS_WEBHOOK }}
Original file line number Diff line number Diff line change 2121 contents : read
2222 security-events : write
2323 id-token : write
24- uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+ uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525 with :
2626 run_version_check : false
2727 run_build : true
3232 project_folder : " trusted-workload/kata-deploy"
3333 secrets :
3434 SYS_ORCH_GITHUB : ${{ secrets.SYS_ORCH_GITHUB }}
35- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
36- COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
3735 NO_AUTH_ECR_PUSH_USERNAME : ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3836 NO_AUTH_ECR_PUSH_PASSWD : ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3937 MSTEAMS_WEBHOOK : ${{ secrets.TEAMS_WEBHOOK }}
Original file line number Diff line number Diff line change 1+ ---
2+ # SPDX-FileCopyrightText: (C) 2025 Intel Corporation
3+ # SPDX-License-Identifier: Apache-2.0
4+
5+ name : Post-Merge Scorecard CI
6+
7+ on :
8+ push :
9+ branches :
10+ - main
11+ workflow_dispatch :
12+
13+ permissions :
14+ contents : read
15+ security-events : write
16+ id-token : write
17+
18+ jobs :
19+ call-scorecard :
20+ uses : open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard.yml@main
21+ with :
22+ project_folder : " ."
23+ secrets :
24+ SYS_ORCH_GITHUB : ${{ secrets.SYS_ORCH_GITHUB }}
Original file line number Diff line number Diff line change 2121 contents : read
2222 security-events : write
2323 id-token : write
24- uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+ uses : open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525 with :
2626 run_version_check : false
2727 run_build : true
3232 project_folder : " trusted-vm"
3333 secrets :
3434 SYS_ORCH_GITHUB : ${{ secrets.SYS_ORCH_GITHUB }}
35- COSIGN_PASSWORD : ${{ secrets.COSIGN_PASSWORD }}
36- COSIGN_PRIVATE_KEY : ${{ secrets.COSIGN_PRIVATE_KEY }}
3735 NO_AUTH_ECR_PUSH_USERNAME : ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3836 NO_AUTH_ECR_PUSH_PASSWD : ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3937 MSTEAMS_WEBHOOK : ${{ secrets.TEAMS_WEBHOOK }}
You can’t perform that action at this time.
0 commit comments