diff --git a/.github/workflows/fossa.yml b/.github/workflows/fossa.yml new file mode 100644 index 000000000..f51e3c172 --- /dev/null +++ b/.github/workflows/fossa.yml @@ -0,0 +1,28 @@ +name: fossa +on: + push: + branches: + - main + - v* + pull_request: + branches: + - main + workflow_dispatch: {} + +permissions: {} + +jobs: + fossa-scan: + if: github.repository_owner == 'spinframework' # FOSSA is not intended to run on forks. + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: "Checkout code" + uses: actions/checkout@v4 + + - name: "Run FOSSA Scan" + uses: fossas/fossa-action@v1.7.0 # Use a specific version if locking is preferred + with: + api-key: ${{ secrets.FOSSA_API_KEY }} + run-tests: true