From 28360a9a4d48559d18c89223521252d16ecb20e1 Mon Sep 17 00:00:00 2001 From: Stephan Schroevers Date: Fri, 24 May 2024 11:37:17 +0200 Subject: [PATCH] Allow OpenSSF Scorecard analysis to access `api.scorecard.dev` --- .github/workflows/openssf-scorecard.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/openssf-scorecard.yml b/.github/workflows/openssf-scorecard.yml index 5510dbf5eb0..3e48c75ef20 100644 --- a/.github/workflows/openssf-scorecard.yml +++ b/.github/workflows/openssf-scorecard.yml @@ -28,6 +28,7 @@ jobs: allowed-endpoints: > api.github.com:443 api.osv.dev:443 + api.scorecard.dev:443 api.securityscorecards.dev:443 fulcio.sigstore.dev:443 github.com:443