Skip to content

fix(ci): scorecard publish requires no global env vars - #19

Merged
wranngle merged 1 commit into
mainfrom
fix/security-scorecard-publish
May 19, 2026
Merged

fix(ci): scorecard publish requires no global env vars#19
wranngle merged 1 commit into
mainfrom
fix/security-scorecard-publish

Conversation

@wranngle

Copy link
Copy Markdown
Owner

Scorecard publish webapp rejects workflows with global env or defaults blocks
(see ossf/scorecard-action#workflow-restrictions). Inline the two version
constants into each job's run step instead.

Test plan

  • security workflow runs green on this branch
  • scorecard job no longer errors with HTTP 400

@github-actions github-actions Bot added the pr-needs-issue PR has no Closes/Fixes/Resolves reference; auto-applied by pr-link-check label May 19, 2026
@github-actions

Copy link
Copy Markdown

This PR needs an issue link.

Add Closes #N / Fixes #N / Resolves #N to the description — or file an issue first via gh-issue.sh. Convention: every PR has an audit trail back to a problem statement.

@wranngle
wranngle merged commit 635dd5c into main May 19, 2026
15 checks passed
@wranngle
wranngle deleted the fix/security-scorecard-publish branch May 19, 2026 03:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr-needs-issue PR has no Closes/Fixes/Resolves reference; auto-applied by pr-link-check

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant