From dbed06147cced0515e9c5b6d55b56c25c076b0f1 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 24 Jun 2026 08:55:06 +0000 Subject: [PATCH] ci(scorecard): adopt standards scorecard-reusable wrapper Replace the standalone OSSF Scorecard job with a thin wrapper around hyperpolymath/standards scorecard-reusable.yml, matching governance.yml. - Pinned to the estate-canonical standards commit 861b5e9 (same as governance.yml) so the estate moves in lockstep. - Grants security-events:write + id-token:write on the calling job: for a reusable call the caller is the ceiling for the called token, so without this the reusable's SARIF upload is silently downgraded and fails. - Keeps the MPL-2.0 header, existing triggers, and the concurrency guardrail. - Leaves scorecard-enforcer.yml standalone (it owns the score-threshold gate and the SECURITY.md / pinned-deps checks the reusable does not cover). Supersedes the scorecard portion of the closed, stale PR #30 (which relicensed these files to PMPL-1.0-or-later against #33 and pinned an older standards SHA). Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01AHygjxRyU3WwmXEhA9KF5L --- .github/workflows/scorecard.yml | 33 ++++++++++++++++----------------- 1 file changed, 16 insertions(+), 17 deletions(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 4d4571e..143842c 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,7 +1,14 @@ # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 +# scorecard.yml — thin wrapper calling the shared OSSF Scorecard analysis in +# hyperpolymath/standards (scorecard-reusable.yml) instead of a per-repo copy, +# matching the governance.yml wrapper. Pinned to the same standards commit as +# governance.yml so the estate moves in lockstep. +# +# scorecard-enforcer.yml deliberately stays standalone: it owns the score +# threshold gate and the SECURITY.md / pinned-deps checks, which the reusable +# does not cover. name: Scorecards supply-chain security - on: branch_protection_rule: schedule: @@ -17,22 +24,14 @@ concurrency: permissions: contents: read jobs: - analysis: - runs-on: ubuntu-latest - timeout-minutes: 15 + scorecard: + # The reusable's analysis job declares security-events:write + id-token:write; + # for a reusable call the caller's grant is the ceiling for the called + # workflow's GITHUB_TOKEN, so these must be granted here or the SARIF upload + # is silently downgraded and fails. (timeout-minutes is intentionally absent: + # it is not a permitted key on a reusable-calling job — the reusable owns it.) permissions: + contents: read security-events: write id-token: write - steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - with: - persist-credentials: false - - name: Run Scorecard - uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.3.1 - with: - results_file: results.sarif - results_format: sarif - - name: Upload results - uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v3.31.8 - with: - sarif_file: results.sarif + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@861b5e911d9e5dcfb3c0ab3dd2a9a3c8fd0a1613