Skip to content

assess(#279/#281): OpenSSF Scorecard baseline workflow - #285

Open
bgonz808 wants to merge 1 commit into
mainfrom
assess/scorecard-baseline
Open

bgonz808 wants to merge 1 commit into
mainfrom
assess/scorecard-baseline

Conversation

@bgonz808

Copy link
Copy Markdown
Owner

External-yardstick baseline for the frameworks epic. Digest-pinned per #221, with the trust asymmetry stated plainly in-file: this is an upstream-authored action (their bytes pinned by SHA, no attestation of ours) — same class as the BinSkim nupkg pin, not the same class as our producer-built tools.

Deliberate choices: publish_results: false (measurement is for us; publishing to the public dataset stays a separate, reversible maintainer decision), no id-token scope since we don't publish, schedule + dispatch only (never PR-triggered — avoids token-scoped jobs on PR), SARIF into our own code-scanning tab beside CodeQL/BinSkim.

There is no existing public Scorecard result for this repo (API returns 404), so this run establishes the baseline. Expect red checks — several will be findings we already track (#261 branch protection / required checks, #176 signed-releases-adjacent), and a red check here is data, not a failure.

External-yardstick measurement for the frameworks epic. Digest-pinned (#221) with
the trust asymmetry stated: upstream-authored action, their bytes pinned by SHA,
no attestation of ours — same class as the BinSkim nupkg pin, not the same class
as producer-built tools.

publish_results: false — results are for us; pushing to the public
securityscorecards.dev dataset stays a separate maintainer decision. No
id-token scope since we do not publish. Schedule + dispatch only, never on PR.
SARIF lands in our own code-scanning tab beside CodeQL/BinSkim.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@bgonz808

Copy link
Copy Markdown
Owner Author

TABLED at maintainer request — do not merge without an explicit ask. Parent epic #279, sibling children #281 (S2C2F) / #282 (CSF 2.0) / #283 (SSDF) / #284 (ISO + CMMC ruling). Priority moved to closing out CI/CD + tooling work first (#280 taxonomy correction, #278 ack-lattice unification, judgment-passing mechanism, soak automation).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant