Conversation
External-yardstick measurement for the frameworks epic. Digest-pinned (#221) with the trust asymmetry stated: upstream-authored action, their bytes pinned by SHA, no attestation of ours — same class as the BinSkim nupkg pin, not the same class as producer-built tools. publish_results: false — results are for us; pushing to the public securityscorecards.dev dataset stays a separate maintainer decision. No id-token scope since we do not publish. Schedule + dispatch only, never on PR. SARIF lands in our own code-scanning tab beside CodeQL/BinSkim. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Owner
Author
|
TABLED at maintainer request — do not merge without an explicit ask. Parent epic #279, sibling children #281 (S2C2F) / #282 (CSF 2.0) / #283 (SSDF) / #284 (ISO + CMMC ruling). Priority moved to closing out CI/CD + tooling work first (#280 taxonomy correction, #278 ack-lattice unification, judgment-passing mechanism, soak automation). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
External-yardstick baseline for the frameworks epic. Digest-pinned per #221, with the trust asymmetry stated plainly in-file: this is an upstream-authored action (their bytes pinned by SHA, no attestation of ours) — same class as the BinSkim nupkg pin, not the same class as our producer-built tools.
Deliberate choices:
publish_results: false(measurement is for us; publishing to the public dataset stays a separate, reversible maintainer decision), noid-tokenscope since we don't publish, schedule + dispatch only (never PR-triggered — avoids token-scoped jobs on PR), SARIF into our own code-scanning tab beside CodeQL/BinSkim.There is no existing public Scorecard result for this repo (API returns 404), so this run establishes the baseline. Expect red checks — several will be findings we already track (#261 branch protection / required checks, #176 signed-releases-adjacent), and a red check here is data, not a failure.