Finding
.github/workflows/scorecard.yml has never run: 20 of 20 runs are startup_failure with jobs = 0, from the first run on 2026-07-19 through the latest scheduled run on 2026-09-21 (run 35561762652). No Scorecard SARIF has ever reached code scanning: the last 30 days of analyses are CodeQL ×58 and Hypatia ×42, Scorecard ×0. Ruleset default-branch-protection (18110203) nevertheless lists Scorecard as a required code_scanning tool, which no PR can satisfy (owner decision surface D85, standards#787).
What it is not
- Not the lockfile:
.github/workflows/actions.lock carries '.github/workflows/scorecard.yml': [] (same shape as the green rust-ci.yml and governance.yml keys) and dependencies: entries for the callee's three inner actions (actions/checkout@3d3c42e5, ossf/scorecard-action@2d114668, actions/upload-artifact@043fb46d).
- Not the allow-list:
ossf/scorecard-action@* is in selected-actions; the callee is same-owner.
- Not the callee:
hyperpolymath/standards/.github/workflows/scorecard-reusable.yml runs green on standards itself (three runs 2026-09-22), hypatia (daily, green 2026-09-22), echo-types, januskey and nextgen-typing.
Caller diff against a green caller (hypatia, comments stripped)
-permissions:
- actions: read
- contents: read
- id-token: write
- security-events: write
+permissions: read-all
on:
+ branch_protection_rule:
schedule:
- - cron: '0 4 * * *'
- workflow_dispatch:
+ - cron: '23 4 * * 1'
jobs:
- scorecard:
- uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
+ analysis:
+ uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4
permissions: {actions: read, contents: read, security-events: write, id-token: write}
secrets: inherit
The workflow-level read-all combined with a reusable-call job that asks for security-events: write and id-token: write is the only structural difference that touches token scopes; the missing workflow_dispatch is why nobody could probe it (a startup death can be event-specific, and there is no way to trigger this file except waiting for Monday 04:23 UTC).
Acceptance criteria
🤖 Generated with Claude Code
Finding
.github/workflows/scorecard.ymlhas never run: 20 of 20 runs arestartup_failurewithjobs = 0, from the first run on 2026-07-19 through the latest scheduled run on 2026-09-21 (run 35561762652). No Scorecard SARIF has ever reached code scanning: the last 30 days of analyses are CodeQL ×58 and Hypatia ×42, Scorecard ×0. Rulesetdefault-branch-protection(18110203) nevertheless lists Scorecard as a requiredcode_scanningtool, which no PR can satisfy (owner decision surface D85, standards#787).What it is not
.github/workflows/actions.lockcarries'.github/workflows/scorecard.yml': [](same shape as the greenrust-ci.ymlandgovernance.ymlkeys) anddependencies:entries for the callee's three inner actions (actions/checkout@3d3c42e5,ossf/scorecard-action@2d114668,actions/upload-artifact@043fb46d).ossf/scorecard-action@*is inselected-actions; the callee is same-owner.hyperpolymath/standards/.github/workflows/scorecard-reusable.ymlruns green on standards itself (three runs 2026-09-22), hypatia (daily, green 2026-09-22), echo-types, januskey and nextgen-typing.Caller diff against a green caller (hypatia, comments stripped)
The workflow-level
read-allcombined with a reusable-call job that asks forsecurity-events: writeandid-token: writeis the only structural difference that touches token scopes; the missingworkflow_dispatchis why nobody could probe it (a startup death can be event-specific, and there is no way to trigger this file except waiting for Monday 04:23 UTC).Acceptance criteria
permissionsgranting exactly the four scopes the job passes,workflow_dispatchadded, callee pinned to the SHA the green callers use (or newer), lock entry kept as[]per the standing job-level-reusable-ref policy.gh workflow run scorecard.ymlproduces a run withjobs > 0and conclusionsuccess; the run id is recorded in this issue.Scorecardanalysis appears inGET /repos/hyperpolymath/absolute-zero/code-scanning/analyses.permissions: read-allalone and dispatching again reproducesstartup_failurewithjobs = 0(or, if it does not, the diagnosis above is wrong and the issue records the real cause).code_scanningrule is re-scoped per D85 before or independently of this cure, so the cure does not gate merges.🤖 Generated with Claude Code