Skip to content

ci(scorecard): cure the 20/20 startup death and emit SARIF (#168) - #169

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/168-scorecard-caller
Sep 22, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/168-scorecard-caller

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

.github/workflows/scorecard.yml has died at startup on every run since 2026-09-07 (startup_failure, jobs=0; #168 counts 20). This PR rewrites the caller in the shape of the standards canonical caller and pins the callee to a revision that actually uploads SARIF. Refs #168 — not closed here: its AC3 is a Scorecard analysis on main, which only the post-merge push: main run can produce.

Root cause (read from the run page; the API carries no log for a jobs=0 run)

The workflow is not valid. .github/workflows/scorecard.yml (Line: 15, Col: 3): Error calling workflow 'hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@bd0df9ea…'. The workflow is requesting 'actions: read, contents: read', but is only allowed 'actions: none, contents: none'.

A job-level permissions: block replaces the workflow-level map. The job carried only security-events: write + id-token: write, so permissions: read-all at the workflow level did nothing for it, and the callee's actions: read / contents: read were refused at startup. #158 (a551037, 09-21) added the two scopes to the job block, but nothing has exercised the file since: it triggered only on branch_protection_rule and a weekly cron (23 4 * * 1, next 09-28) and had no workflow_dispatch.

Change

before (main 828399a) after
workflow permissions read-all contents: read (standards shape)
job permissions four scopes (since #158) four scopes (unchanged)
triggers branch_protection_rule, cron + push: main, pull_request, workflow_dispatch
concurrency none ${{ github.workflow }}-${{ github.ref }}, cancel-in-progress
callee pin standards bd0df9ea — results_format: json, no SARIF upload, so no analysis even when green standards 0f13f51f — results_format: sarif + upload-sarif, PR lane in Local mode; green on standards push run 35794990055 and pull_request run 35795130513
secrets: inherit yes dropped — the callee references no secrets.
actions.lock key '.github/workflows/scorecard.yml': [] unchanged; a callee's steps are not validated against the caller's lock (hypatia-scan is the control). gh actions-lock --verify-local: 16/16 workflows covered

Deliberate differences from the standards caller: the cross-repo SHA pin, this repo's existing cron, and the branch_protection_rule trigger (kept, not mine to drop). The workflow name is unchanged so check-run history is not orphaned.

Evidence (all three dispatched 2026-09-22T23:26:30Z)

branch shape run result
fix/168-scorecard-caller 6f01307 (this PR) cure 35797429801 passed startup, jobs=2. Run Scorecard then failed inside ossf/scorecard-action: refs/heads/fix/168-scorecard-caller not supported with workflow_dispatch event. Only the default branch main is supported. The action refuses non-default branches by design; its supported lanes are pull_request (this PR's check) and push: main (after merge).
mutant/168-a-readall-two-scopes 45f97fb read-all + a job block of only security-events/id-token (the pre-#158 shape) 35797435300 startup_failure, jobs=0: "The nested job 'scorecard' is requesting 'actions: read, contents: read', but is only allowed 'actions: none, contents: none'." The diagnosed cause, reproduced one-variable.
mutant/168-b-readall-four-scopes 867847c read-all + four job scopes (issue #168's own AC4 mutant) 35797440576 passed startup, then the same in-action refusal as the cure. So read-all alone was never the killer, #158's job block had already cured startup, and the AC4 mutant as written in the issue was the wrong shape.

The mutant branches are deleted; the runs persist.

What the PR lane must show before this merges

  • scorecard / Run Scorecard PR green on refs/pull/N/merge (Local mode, publish_results: false), and a Scorecard entry under code-scanning/analyses for the PR ref.
  • Every rule of ruleset 18110203 passing: required_status_checks, code_scanning (CodeQL, Hypatia, Scorecard), required_signatures, review-thread resolution. Auto-merge by squash is armed only once every check is green (D87); nothing is merged over a red.
  • After merge: the push: main run produces the Scorecard analysis on main (scorecard.yml has never run: 20/20 startup_failure (jobs=0); Scorecard is a required code_scanning tool with zero analyses #168 AC3), and workflow_dispatch on main works (the action supports the default branch).

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

Root cause, read from the run page of every failed run since 09-07:
"The workflow is requesting 'actions: read, contents: read', but is
only allowed 'actions: none, contents: none'." A job-level
`permissions:` block REPLACES the workflow-level map, so the job that
carried only `security-events: write` + `id-token: write` left the
callee's `actions: read` / `contents: read` at `none`, and the runner
refused the call at startup (jobs=0, startup_failure). #158 added the
two scopes on 09-21 but nothing has exercised the file since: it runs
only on `branch_protection_rule` and a weekly cron, with no dispatch.

Cure, in the shape of the standards canonical caller:
- workflow-level `permissions: contents: read`, job-level the four
  scopes the callee's jobs request (actions/contents read,
  security-events/id-token write);
- triggers: push to main, pull_request, workflow_dispatch, plus the
  existing branch_protection_rule and '23 4 * * 1' cron;
- concurrency group per ref, cancel-in-progress;
- callee pinned to standards 0f13f51f, which emits `results_format:
  sarif` and uploads it (bd0df9ea emitted JSON and uploaded nothing,
  so a green run would still have produced no Scorecard analysis);
- `secrets: inherit` dropped: the callee references no secrets.

Lock key `.github/workflows/scorecard.yml: []` is unchanged; the
callee's steps are not validated against the caller's lock
(hypatia-scan is the control). `gh actions-lock --verify-local`: all
16 workflows covered.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 11 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 43292964-4f08-4127-a871-d677627c4dca

📥 Commits

Reviewing files that changed from the base of the PR and between 828399a and 6f01307.

📒 Files selected for processing (1)
  • .github/workflows/scorecard.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant