File tree 1 file changed +12
-4
lines changed
1 file changed +12
-4
lines changed Original file line number Diff line number Diff line change 28
28
id-token : write
29
29
contents : read
30
30
actions : read
31
- env :
32
- CHAINLOOP_WORKFLOW_NAME : " chainloop-vault-scorecards"
33
- CHAINLOOP_PROJECT : " chainloop"
34
- CHAINLOOP_TOKEN : ${{ secrets.CHAINLOOP_TOKEN }}
35
31
36
32
steps :
37
33
- name : Install Chainloop
46
42
- name : Initialize Attestation
47
43
run : |
48
44
chainloop attestation init --workflow $CHAINLOOP_WORKFLOW_NAME --project $CHAINLOOP_PROJECT
45
+ env :
46
+ CHAINLOOP_WORKFLOW_NAME : " chainloop-vault-scorecards"
47
+ CHAINLOOP_PROJECT : " chainloop"
48
+ CHAINLOOP_TOKEN : ${{ secrets.CHAINLOOP_TOKEN }}
49
49
50
50
- name : " Run analysis"
51
51
uses : ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1
@@ -87,18 +87,26 @@ jobs:
87
87
- name : Attest analysis
88
88
run : |
89
89
chainloop attestation add --name sarif-results --value results.sarif
90
+ env :
91
+ CHAINLOOP_TOKEN : ${{ secrets.CHAINLOOP_TOKEN }}
90
92
91
93
- name : Finish and Record Attestation
92
94
if : ${{ success() }}
93
95
run : |
94
96
chainloop attestation push
97
+ env :
98
+ CHAINLOOP_TOKEN : ${{ secrets.CHAINLOOP_TOKEN }}
95
99
96
100
- name : Mark attestation as failed
97
101
if : ${{ failure() }}
98
102
run : |
99
103
chainloop attestation reset
104
+ env :
105
+ CHAINLOOP_TOKEN : ${{ secrets.CHAINLOOP_TOKEN }}
100
106
101
107
- name : Mark attestation as cancelled
102
108
if : ${{ cancelled() }}
103
109
run : |
104
110
chainloop attestation reset --trigger cancellation
111
+ env :
112
+ CHAINLOOP_TOKEN : ${{ secrets.CHAINLOOP_TOKEN }}
You can’t perform that action at this time.
0 commit comments