Skip to content

gha: fossa license scanning #3

gha: fossa license scanning

gha: fossa license scanning #3

name: FOSSA License Scanning
on:
push:
branches:
- main
pull_request:
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout tree
uses: actions/checkout@v4
- name: Run FOSSA scan and upload build data
uses: fossa-contrib/fossa-action@v3
with:
# push-only token, intentional; see https://github.com/fossa-contrib/fossa-action?tab=readme-ov-file#push-only-api-token
# this also how other CNCF projects are doing e.g. https://github.com/cncf/foundation/issues/109
fossa-api-key: 80871bdd477c2c97f65e9822cae99d20