Skip to content

fix(scorecard): in-repo canonical workflow (startup_failure on main)#191

Merged
cdeust merged 1 commit into
mainfrom
fix/scorecard-in-repo
Jul 25, 2026
Merged

fix(scorecard): in-repo canonical workflow (startup_failure on main)#191
cdeust merged 1 commit into
mainfrom
fix/scorecard-in-repo

Conversation

@cdeust

@cdeust cdeust commented Jul 25, 2026

Copy link
Copy Markdown
Owner

Post-merge repair: the supply-chain sweep's Scorecard call-site produced startup_failure on main (zero jobs) — a failure class PR CI structurally cannot catch since the workflow only triggers on main/schedule. Cross-repo reusable calls also cannot satisfy scorecard-action's publish_results OIDC requirement. Replaced with the canonical in-repo template (same pinned SHAs as AP's working definition). Verification plan: merge → workflow_dispatch the Scorecard → assert the run starts and completes.

🤖 Generated with Claude Code

… cannot start or publish

startup_failure on main (0 jobs) after the green PR merged: this
workflow class only triggers on main/schedule, so PR CI structurally
cannot validate it. OSSF publish_results additionally requires the
analyzed repo's own workflow as OIDC subject. Same pinned SHAs as the
AP definition; workflow_dispatch retained for post-merge verification.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cdeust
cdeust merged commit fc2a8b6 into main Jul 25, 2026
14 checks passed
@cdeust
cdeust deleted the fix/scorecard-in-repo branch July 25, 2026 20:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant