Skip to content

scorecard.yml has never run: 20/20 startup_failure (jobs=0); Scorecard is a required code_scanning tool with zero analyses #168

Description

@hyperpolymath

Finding

.github/workflows/scorecard.yml has never run: 20 of 20 runs are startup_failure with jobs = 0, from the first run on 2026-07-19 through the latest scheduled run on 2026-09-21 (run 35561762652). No Scorecard SARIF has ever reached code scanning: the last 30 days of analyses are CodeQL ×58 and Hypatia ×42, Scorecard ×0. Ruleset default-branch-protection (18110203) nevertheless lists Scorecard as a required code_scanning tool, which no PR can satisfy (owner decision surface D85, standards#787).

What it is not

  • Not the lockfile: .github/workflows/actions.lock carries '.github/workflows/scorecard.yml': [] (same shape as the green rust-ci.yml and governance.yml keys) and dependencies: entries for the callee's three inner actions (actions/checkout@3d3c42e5, ossf/scorecard-action@2d114668, actions/upload-artifact@043fb46d).
  • Not the allow-list: ossf/scorecard-action@* is in selected-actions; the callee is same-owner.
  • Not the callee: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml runs green on standards itself (three runs 2026-09-22), hypatia (daily, green 2026-09-22), echo-types, januskey and nextgen-typing.

Caller diff against a green caller (hypatia, comments stripped)

-permissions:
-  actions: read
-  contents: read
-  id-token: write
-  security-events: write
+permissions: read-all
 on:
+  branch_protection_rule:
   schedule:
-    - cron: '0 4 * * *'
-  workflow_dispatch:
+    - cron: '23 4 * * 1'
 jobs:
-  scorecard:
-    uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
+  analysis:
+    uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4
     permissions: {actions: read, contents: read, security-events: write, id-token: write}
     secrets: inherit

The workflow-level read-all combined with a reusable-call job that asks for security-events: write and id-token: write is the only structural difference that touches token scopes; the missing workflow_dispatch is why nobody could probe it (a startup death can be event-specific, and there is no way to trigger this file except waiting for Monday 04:23 UTC).

Acceptance criteria

  • Caller rewritten to the estate shape: explicit workflow-level permissions granting exactly the four scopes the job passes, workflow_dispatch added, callee pinned to the SHA the green callers use (or newer), lock entry kept as [] per the standing job-level-reusable-ref policy.
  • gh workflow run scorecard.yml produces a run with jobs > 0 and conclusion success; the run id is recorded in this issue.
  • A Scorecard analysis appears in GET /repos/hyperpolymath/absolute-zero/code-scanning/analyses.
  • Mutant: restoring permissions: read-all alone and dispatching again reproduces startup_failure with jobs = 0 (or, if it does not, the diagnosis above is wrong and the issue records the real cause).
  • Ruleset 18110203's code_scanning rule is re-scoped per D85 before or independently of this cure, so the cure does not gate merges.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething is broken or behaves incorrectlycicdCI/CD: workflows, actions, lockfiles, pins, runners, release gates

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions