chore: issue sweep — dead Justfile recipes, stray MAINTAINERS, stale pointers #239
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # Thin wrapper around hyperpolymath/standards scorecard-reusable.yml, in the | |
| # shape of the standards caller (standards/.github/workflows/scorecard.yml). | |
| # Deliberate differences from that caller: the cross-repo SHA pin, this repo's | |
| # existing weekly cron, and the branch_protection_rule trigger. See #168. | |
| name: Scorecards supply-chain security | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branch_protection_rule: | |
| schedule: | |
| - cron: '23 4 * * 1' | |
| workflow_dispatch: | |
| # Estate guardrail: cancel superseded runs so re-pushes don't pile up. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| # A job-level `permissions:` block REPLACES the workflow-level map, so the | |
| # calling job below must itself grant every scope the callee's jobs request: | |
| # actions: read (Scorecard's Packaging check), contents: read (checkout), | |
| # security-events: write (SARIF upload), id-token: write (OIDC publication). | |
| # This file died at startup 20/20 times while the job block carried only | |
| # security-events + id-token, which left actions and contents at `none` (#168). | |
| permissions: | |
| contents: read | |
| jobs: | |
| scorecard: | |
| permissions: | |
| actions: read | |
| contents: read | |
| security-events: write | |
| id-token: write | |
| uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@0f13f51fafe9d2b670252aa2a18993223bffdece |