Commit aaae441
fix(ci): disable scorecard publish_results (was 400ing on webapp)
Scorecard analysis runs fine (score 7.0) but publish_results=true POSTs to
the OpenSSF webapp, which rejects the top-level security-events:write perm
(workflow-restrictions). Set publish_results=false; SARIF still uploads to
GitHub code-scanning.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 25c8059 commit aaae441
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| |||
0 commit comments