Skip to content

Commit 770441f

Browse files
ci(scorecard-enforcer): split score-threshold from publish job (OSSF run-step ban) (#37)
## Summary This repo's `scorecard-enforcer.yml` has the OSSF publish-contract violation that hyperpolymath/standards#304 fixed in the canonical template. Every Scorecard run fails with: ``` webapp: scorecard job must only have steps with uses ``` ## Root cause OSSF's publish endpoint enforces a hard contract: the job that runs `ossf/scorecard-action` with `publish_results: true` must contain ONLY `uses:` steps. The pre-fix template's "Check minimum score" `run:` step in the same job fails the publish step and the whole workflow run. ## Fix Replace local file with the post-#304 standards template: - `scorecard` job: uses-only (now includes `upload-artifact` for SARIF hand-off) - `check-score` job: `needs: scorecard`, downloads artifact, runs the threshold gate ## Detection going forward Hypatia rule WF014 in hyperpolymath/hypatia#393 catches this pattern. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 30c377e commit 770441f

1 file changed

Lines changed: 42 additions & 6 deletions

File tree

.github/workflows/scorecard-enforcer.yml

Lines changed: 42 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -9,34 +9,70 @@ on:
99
- cron: '0 6 * * 1' # Weekly on Monday
1010
workflow_dispatch:
1111

12-
permissions: read-all
12+
# Estate guardrail: cancel superseded runs so re-pushes / rebased PR
13+
# updates do not pile up queued runs against the shared account-wide
14+
# Actions concurrency pool. Applied only to read-only check workflows
15+
# (no publish/mutation), so cancelling a superseded run is always safe.
16+
concurrency:
17+
group: ${{ github.workflow }}-${{ github.ref }}
18+
cancel-in-progress: true
19+
20+
permissions:
21+
contents: read
1322

1423
jobs:
24+
# The OSSF Scorecard publish endpoint enforces a hard contract: the job that
25+
# runs `ossf/scorecard-action` with `publish_results: true` must contain
26+
# ONLY steps with `uses:` (no `run:` steps in the same job). If a `run:`
27+
# step is present, the publish step fails with:
28+
# "webapp: scorecard job must only have steps with uses"
29+
# (49 estate repos hit this; see ROADMAP audit 2026-05-30.)
30+
#
31+
# Fix: split the threshold check into a downstream job that depends on
32+
# `scorecard` and consumes the SARIF artifact. The `scorecard` job stays
33+
# uses-only; `check-score` is the gating job that emits the error.
1534
scorecard:
1635
runs-on: ubuntu-latest
1736
permissions:
1837
security-events: write
1938
id-token: write # For OIDC
2039
steps:
21-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
40+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2241
with:
2342
persist-credentials: false
2443

2544
- name: Run Scorecard
26-
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
45+
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
2746
with:
2847
results_file: results.sarif
2948
results_format: sarif
3049
publish_results: true
3150

3251
- name: Upload SARIF
33-
uses: github/codeql-action/upload-sarif@662472033e021d55d94146f66f6058822b0b39fd # v3
52+
uses: github/codeql-action/upload-sarif@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4
3453
with:
3554
sarif_file: results.sarif
3655

56+
- name: Persist SARIF for downstream score-gate job
57+
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
58+
with:
59+
name: scorecard-results
60+
path: results.sarif
61+
retention-days: 1
62+
63+
check-score:
64+
needs: scorecard
65+
runs-on: ubuntu-latest
66+
permissions:
67+
contents: read
68+
steps:
69+
- name: Download SARIF from scorecard job
70+
uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v5.0.0
71+
with:
72+
name: scorecard-results
73+
3774
- name: Check minimum score
3875
run: |
39-
# Parse score from results
4076
SCORE=$(jq -r '.runs[0].tool.driver.properties.score // 0' results.sarif 2>/dev/null || echo "0")
4177
4278
echo "OpenSSF Scorecard Score: $SCORE"
@@ -53,7 +89,7 @@ jobs:
5389
check-critical:
5490
runs-on: ubuntu-latest
5591
steps:
56-
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
92+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
5793

5894
- name: Check SECURITY.md exists
5995
run: |

0 commit comments

Comments
 (0)