Skip to content

Commit e890ab2

Browse files
authored
adding scorecard workflow bump to 0.1.62 (#266)
1 parent 2a8750d commit e890ab2

File tree

7 files changed

+30
-18
lines changed

7 files changed

+30
-18
lines changed

.github/workflows/post-merge-attestation-manager.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
contents: read
2323
security-events: write
2424
id-token: write
25-
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
25+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2626
with:
2727
run_version_check: false
2828
run_build: true
@@ -33,8 +33,6 @@ jobs:
3333
project_folder: "attestation-manager"
3434
secrets:
3535
SYS_ORCH_GITHUB: ${{ secrets.SYS_ORCH_GITHUB }}
36-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
37-
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
3836
NO_AUTH_ECR_PUSH_USERNAME: ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3937
NO_AUTH_ECR_PUSH_PASSWD: ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
4038
MSTEAMS_WEBHOOK: ${{ secrets.TEAMS_WEBHOOK }}

.github/workflows/post-merge-attestation-verifier.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
contents: read
2222
security-events: write
2323
id-token: write
24-
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525
with:
2626
run_version_check: false
2727
run_build: true
@@ -32,8 +32,6 @@ jobs:
3232
project_folder: "attestation-verifier"
3333
secrets:
3434
SYS_ORCH_GITHUB: ${{ secrets.SYS_ORCH_GITHUB }}
35-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
36-
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
3735
NO_AUTH_ECR_PUSH_USERNAME: ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3836
NO_AUTH_ECR_PUSH_PASSWD: ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3937
MSTEAMS_WEBHOOK: ${{ secrets.TEAMS_WEBHOOK }}

.github/workflows/post-merge-baremetal.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
contents: read
2323
security-events: write
2424
id-token: write
25-
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
25+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2626
with:
2727
run_version_check: false
2828
run_build: true
@@ -34,8 +34,6 @@ jobs:
3434
project_folder: "baremetal"
3535
secrets:
3636
SYS_ORCH_GITHUB: ${{ secrets.SYS_ORCH_GITHUB }}
37-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
38-
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
3937
NO_AUTH_ECR_PUSH_USERNAME: ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
4038
NO_AUTH_ECR_PUSH_PASSWD: ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
4139
MSTEAMS_WEBHOOK: ${{ secrets.TEAMS_WEBHOOK }}

.github/workflows/post-merge-helm.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
contents: read
2222
security-events: write
2323
id-token: write
24-
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525
with:
2626
run_build: false
2727
run_helm_build: true
@@ -31,8 +31,6 @@ jobs:
3131
project_folder: "helm"
3232
secrets:
3333
SYS_ORCH_GITHUB: ${{ secrets.SYS_ORCH_GITHUB }}
34-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
35-
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
3634
NO_AUTH_ECR_PUSH_USERNAME: ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3735
NO_AUTH_ECR_PUSH_PASSWD: ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3836
MSTEAMS_WEBHOOK: ${{ secrets.TEAMS_WEBHOOK }}

.github/workflows/post-merge-kata-deploy.yaml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
contents: read
2222
security-events: write
2323
id-token: write
24-
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525
with:
2626
run_version_check: false
2727
run_build: true
@@ -32,8 +32,6 @@ jobs:
3232
project_folder: "trusted-workload/kata-deploy"
3333
secrets:
3434
SYS_ORCH_GITHUB: ${{ secrets.SYS_ORCH_GITHUB }}
35-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
36-
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
3735
NO_AUTH_ECR_PUSH_USERNAME: ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3836
NO_AUTH_ECR_PUSH_PASSWD: ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3937
MSTEAMS_WEBHOOK: ${{ secrets.TEAMS_WEBHOOK }}
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
---
2+
# SPDX-FileCopyrightText: (C) 2025 Intel Corporation
3+
# SPDX-License-Identifier: Apache-2.0
4+
5+
name: Post-Merge Scorecard CI
6+
7+
on:
8+
push:
9+
branches:
10+
- main
11+
workflow_dispatch:
12+
13+
permissions:
14+
contents: read
15+
security-events: write
16+
id-token: write
17+
18+
jobs:
19+
call-scorecard:
20+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard.yml@main
21+
with:
22+
project_folder: "."
23+
secrets:
24+
SYS_ORCH_GITHUB: ${{ secrets.SYS_ORCH_GITHUB }}

.github/workflows/post-merge-trusted-vm.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
contents: read
2222
security-events: write
2323
id-token: write
24-
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@c4b86434962d13f65fd7b16a33e9eecfd5849a64 # v0.1.56
24+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge.yml@da08a06e8aec70621e50ed4aec2fac5599839f45 # v0.1.62
2525
with:
2626
run_version_check: false
2727
run_build: true
@@ -32,8 +32,6 @@ jobs:
3232
project_folder: "trusted-vm"
3333
secrets:
3434
SYS_ORCH_GITHUB: ${{ secrets.SYS_ORCH_GITHUB }}
35-
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
36-
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
3735
NO_AUTH_ECR_PUSH_USERNAME: ${{ secrets.NO_AUTH_ECR_PUSH_USERNAME }}
3836
NO_AUTH_ECR_PUSH_PASSWD: ${{ secrets.NO_AUTH_ECR_PUSH_PASSWD }}
3937
MSTEAMS_WEBHOOK: ${{ secrets.TEAMS_WEBHOOK }}

0 commit comments

Comments
 (0)