Skip to content

Commit 255a640

Browse files
ci(scorecard-enforcer): split score-threshold from publish job (OSSF run-step ban) (#99)
## Summary This repo's `scorecard-enforcer.yml` has the OSSF publish-contract violation that hyperpolymath/standards#304 fixed in the canonical template. Every Scorecard run fails with: ``` webapp: scorecard job must only have steps with uses ``` ## Root cause OSSF's publish endpoint enforces a hard contract: the job that runs `ossf/scorecard-action` with `publish_results: true` must contain ONLY `uses:` steps. The pre-fix template's "Check minimum score" `run:` step in the same job fails the publish step and the whole workflow run. ## Fix Replace local file with the post-#304 standards template: - `scorecard` job: uses-only (now includes `upload-artifact` for SARIF hand-off) - `check-score` job: `needs: scorecard`, downloads artifact, runs the threshold gate ## Detection going forward Hypatia rule WF014 in hyperpolymath/hypatia#393 catches this pattern. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 6f1b623 commit 255a640

1 file changed

Lines changed: 38 additions & 13 deletions

File tree

.github/workflows/scorecard-enforcer.yml

Lines changed: 38 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# SPDX-License-Identifier: PMPL-1.0-or-later
1+
# SPDX-License-Identifier: MPL-2.0
22
# Prevention workflow - runs OpenSSF Scorecard and fails on low scores
33
name: OpenSSF Scorecard Enforcer
44

@@ -21,6 +21,16 @@ permissions:
2121
contents: read
2222

2323
jobs:
24+
# The OSSF Scorecard publish endpoint enforces a hard contract: the job that
25+
# runs `ossf/scorecard-action` with `publish_results: true` must contain
26+
# ONLY steps with `uses:` (no `run:` steps in the same job). If a `run:`
27+
# step is present, the publish step fails with:
28+
# "webapp: scorecard job must only have steps with uses"
29+
# (49 estate repos hit this; see ROADMAP audit 2026-05-30.)
30+
#
31+
# Fix: split the threshold check into a downstream job that depends on
32+
# `scorecard` and consumes the SARIF artifact. The `scorecard` job stays
33+
# uses-only; `check-score` is the gating job that emits the error.
2434
scorecard:
2535
runs-on: ubuntu-latest
2636
permissions:
@@ -36,29 +46,44 @@ jobs:
3646
with:
3747
results_file: results.sarif
3848
results_format: sarif
39-
publish_results: false
49+
publish_results: true
4050

4151
- name: Upload SARIF
4252
uses: github/codeql-action/upload-sarif@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4
4353
with:
4454
sarif_file: results.sarif
4555

56+
- name: Persist SARIF for downstream score-gate job
57+
uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
58+
with:
59+
name: scorecard-results
60+
path: results.sarif
61+
retention-days: 1
62+
63+
check-score:
64+
needs: scorecard
65+
runs-on: ubuntu-latest
66+
permissions:
67+
contents: read
68+
steps:
69+
- name: Download SARIF from scorecard job
70+
uses: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v5.0.0
71+
with:
72+
name: scorecard-results
73+
4674
- name: Check minimum score
4775
run: |
48-
# Parse overall score from SARIF.
49-
# The scorecard-action SARIF uses a non-standard property path;
50-
# fall back to the tool version string which embeds the score.
51-
# Note: this step is informational only (enforcer score gating
52-
# is handled by the OSSF webapp via scorecard.yml publish).
53-
SCORE=$(jq -r '
54-
.runs[0].properties.metricResults[]? |
55-
select(.id == "AggregateScore") | .value
56-
' results.sarif 2>/dev/null || echo "unknown")
76+
SCORE=$(jq -r '.runs[0].tool.driver.properties.score // 0' results.sarif 2>/dev/null || echo "0")
5777
5878
echo "OpenSSF Scorecard Score: $SCORE"
5979
60-
# Score check is advisory — do not fail the workflow here.
61-
# Hard enforcement is via scorecard.yml + OSSF webapp badge.
80+
# Minimum acceptable score (0-10 scale)
81+
MIN_SCORE=5
82+
83+
if [ "$(echo "$SCORE < $MIN_SCORE" | bc -l)" = "1" ]; then
84+
echo "::error::Scorecard score $SCORE is below minimum $MIN_SCORE"
85+
exit 1
86+
fi
6287
6388
# Check specific high-priority items
6489
check-critical:

0 commit comments

Comments
 (0)