Commit a27471d
fix(ci): pin the long-tail actions and retire scorecard-enforcer.yml
Closes the two residual `governance` failures left by the first sweep:
* `Workflow security linter` reported "Found unpinned actions" for actions
outside the first pass's pin map (docker/*, slsa, julia-actions, softprops,
ipdxco, codeql upload-sarif). Floating branch refs (@main / @master) are
left alone on purpose — pinning those is a version decision.
* `Check Workflow Staleness` errors on `scorecard-enforcer.yml` by name (it
is retired in favour of scorecard.yml -> standards scorecard-reusable.yml)
and separately on Scorecard uploading SARIF to Code Scanning. Removing the
retired file resolves both. It is removed only where scorecard.yml already
exists, so Scorecard coverage is retained.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>1 parent 6850a67 commit a27471d
1 file changed
Lines changed: 0 additions & 81 deletions
This file was deleted.
0 commit comments