Skip to content

Commit bf99764

Browse files
authored
fix(github): Move env from top level to steps (#1725)
Signed-off-by: Javier Rodriguez <[email protected]>
1 parent f5505a3 commit bf99764

File tree

1 file changed

+12
-4
lines changed

1 file changed

+12
-4
lines changed

.github/workflows/scorecards.yml

+12-4
Original file line numberDiff line numberDiff line change
@@ -28,10 +28,6 @@ jobs:
2828
id-token: write
2929
contents: read
3030
actions: read
31-
env:
32-
CHAINLOOP_WORKFLOW_NAME: "chainloop-vault-scorecards"
33-
CHAINLOOP_PROJECT: "chainloop"
34-
CHAINLOOP_TOKEN: ${{ secrets.CHAINLOOP_TOKEN }}
3531

3632
steps:
3733
- name: Install Chainloop
@@ -46,6 +42,10 @@ jobs:
4642
- name: Initialize Attestation
4743
run: |
4844
chainloop attestation init --workflow $CHAINLOOP_WORKFLOW_NAME --project $CHAINLOOP_PROJECT
45+
env:
46+
CHAINLOOP_WORKFLOW_NAME: "chainloop-vault-scorecards"
47+
CHAINLOOP_PROJECT: "chainloop"
48+
CHAINLOOP_TOKEN: ${{ secrets.CHAINLOOP_TOKEN }}
4949

5050
- name: "Run analysis"
5151
uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1
@@ -87,18 +87,26 @@ jobs:
8787
- name: Attest analysis
8888
run: |
8989
chainloop attestation add --name sarif-results --value results.sarif
90+
env:
91+
CHAINLOOP_TOKEN: ${{ secrets.CHAINLOOP_TOKEN }}
9092

9193
- name: Finish and Record Attestation
9294
if: ${{ success() }}
9395
run: |
9496
chainloop attestation push
97+
env:
98+
CHAINLOOP_TOKEN: ${{ secrets.CHAINLOOP_TOKEN }}
9599

96100
- name: Mark attestation as failed
97101
if: ${{ failure() }}
98102
run: |
99103
chainloop attestation reset
104+
env:
105+
CHAINLOOP_TOKEN: ${{ secrets.CHAINLOOP_TOKEN }}
100106

101107
- name: Mark attestation as cancelled
102108
if: ${{ cancelled() }}
103109
run: |
104110
chainloop attestation reset --trigger cancellation
111+
env:
112+
CHAINLOOP_TOKEN: ${{ secrets.CHAINLOOP_TOKEN }}

0 commit comments

Comments
 (0)