From a1fd214713c61dff4e6dbf4d39cde0e9ff31289c Mon Sep 17 00:00:00 2001 From: Victor Lyuboslavsky <2685025+getvictor@users.noreply.github.com> Date: Mon, 8 Dec 2025 09:23:38 -0600 Subject: [PATCH] Adding Gradle wrapper validator (#36817) Resolves https://github.com/fleetdm/fleet/security/code-scanning/1484 Fix uses OSSF feature: https://github.com/ossf/scorecard/issues/1815 --- .github/workflows/scorecards-analysis.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/scorecards-analysis.yml b/.github/workflows/scorecards-analysis.yml index c1fba8fcd8..72c912ef3d 100644 --- a/.github/workflows/scorecards-analysis.yml +++ b/.github/workflows/scorecards-analysis.yml @@ -34,6 +34,9 @@ jobs: with: persist-credentials: false + - name: Validate Gradle wrapper + uses: gradle/actions/wrapper-validation@4d9f0ba0025fe599b4ebab900eb7f3a1d93ef4c2 # v5.0.0 + - name: "Run analysis" uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1 with: