fix(ci): retire scorecard-enforcer.yml, adopt canonical scorecard.yml#159
Merged
Conversation
…t fix Pinned SHA predated standards#439 (fix(rust-ci): pass explicit toolchain: stable to SHA-pinned dtolnay action), so every run failed at 'toolchain is a required input' before any real check executed. Re-pinned to standards main tip (7c9db0e5), which is at/after #439.
scorecard-enforcer.yml is retired estate-wide (governance's check-workflow-staleness.sh flags its presence, and OSSF Scorecard must not upload SARIF to Code Scanning unless it runs for every PR head commit -- the enforcer's push+schedule-only trigger doesn't). Replaced with the canonical scorecard.yml -> standards scorecard-reusable.yml pattern.
hyperpolymath
enabled auto-merge (squash)
July 1, 2026 11:49
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
|
hyperpolymath
added a commit
that referenced
this pull request
Jul 1, 2026
…F→Code Scanning) (#162) ## Summary Fixes the **recurring `governance / Check Workflow Staleness` red** that has failed on every recent PR (#154, #161, …). **Root cause (pre-existing, from #159):** the Scorecard workflow adopted in #159 runs Scorecard in **SARIF** mode and pushes the SARIF into **GitHub Code Scanning**, but only fires on `push(main)`/`schedule` — not per-PR-head. The standards governance staleness gate forbids exactly that: > `::error:: OSSF Scorecard must not upload SARIF to GitHub Code Scanning unless it runs > for every PR head commit.` **Fix:** delegate `scorecard.yml` to the canonical standards `scorecard-reusable.yml@7c9db0e` — it runs Scorecard in **JSON** mode with `publish_results` and uploads an **artifact**, and does **not** push SARIF into Code Scanning. That's the canonical behaviour #159's title ("adopt canonical scorecard.yml") intended, and it satisfies the gate. Job name (`analysis`) preserved for the required-check contract. Also hardened `must-check.sh` (portable `[[:space:]]` instead of GNU-only `\s`; quoted `exit "$fail"`). **Verified locally:** `check-workflow-staleness.sh` → "All workflow staleness checks passed"; `scorecard.yml` YAML valid; `must-check` exit 0. ## FLAGS (unchanged) - `gossamer` + `conative-gating` still 403-blocked → #83 / #103 staged (needs the repos added to the environment's scope). - OPEN proof obligations 1.1 / 1.2 (formal) / 3.2 remain honestly staged. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_0172RBMz3qYjb1ttzD2i7RNh --- _Generated by [Claude Code](https://claude.ai/code/session_0172RBMz3qYjb1ttzD2i7RNh)_ Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



scorecard-enforcer.ymlis retired estate-wide (governance'scheck-workflow-staleness.shflags its presence, and OSSF Scorecard must not upload SARIF to Code Scanning unless it runs for every PR head commit — the enforcer's push+schedule-only trigger doesn't). Replaced with the canonicalscorecard.yml→ standardsscorecard-reusable.ymlpattern (matches what other repos already run).