diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 4d4571e..143842c 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,7 +1,14 @@ # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 +# scorecard.yml — thin wrapper calling the shared OSSF Scorecard analysis in +# hyperpolymath/standards (scorecard-reusable.yml) instead of a per-repo copy, +# matching the governance.yml wrapper. Pinned to the same standards commit as +# governance.yml so the estate moves in lockstep. +# +# scorecard-enforcer.yml deliberately stays standalone: it owns the score +# threshold gate and the SECURITY.md / pinned-deps checks, which the reusable +# does not cover. name: Scorecards supply-chain security - on: branch_protection_rule: schedule: @@ -17,22 +24,14 @@ concurrency: permissions: contents: read jobs: - analysis: - runs-on: ubuntu-latest - timeout-minutes: 15 + scorecard: + # The reusable's analysis job declares security-events:write + id-token:write; + # for a reusable call the caller's grant is the ceiling for the called + # workflow's GITHUB_TOKEN, so these must be granted here or the SARIF upload + # is silently downgraded and fails. (timeout-minutes is intentionally absent: + # it is not a permitted key on a reusable-calling job — the reusable owns it.) permissions: + contents: read security-events: write id-token: write - steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - with: - persist-credentials: false - - name: Run Scorecard - uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.3.1 - with: - results_file: results.sarif - results_format: sarif - - name: Upload results - uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v3.31.8 - with: - sarif_file: results.sarif + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@861b5e911d9e5dcfb3c0ab3dd2a9a3c8fd0a1613