Skip to content

Add OSV-Scanner

Add OSV-Scanner #2

name: OSV-Scanner PR Scan
# Change "main" to your default branch if you use a different name, i.e. "master"
on:
pull_request:
branches:
- main
push:
branches:
- main
# Declare default permissions as read only.
permissions: read-all
jobs:
scan-pr:
uses: "google/osv-scanner/.github/workflows/osv-scanner-reusable-pr.yml@main"
permissions:
# Needed to upload the SARIF results to code-scanning dashboard.
security-events: write
contents: read