diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index daab17b..a000aa5 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,22 +1,40 @@ # This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. -# This workflow is managed by gh actions-lock. +# Thin wrapper around hyperpolymath/standards scorecard-reusable.yml, in the +# shape of the standards caller (standards/.github/workflows/scorecard.yml). +# Deliberate differences from that caller: the cross-repo SHA pin, this repo's +# existing weekly cron, and the branch_protection_rule trigger. See #168. + name: Scorecards supply-chain security on: + push: + branches: [main] + pull_request: branch_protection_rule: schedule: - cron: '23 4 * * 1' + workflow_dispatch: + +# Estate guardrail: cancel superseded runs so re-pushes don't pile up. +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true -permissions: read-all +# A job-level `permissions:` block REPLACES the workflow-level map, so the +# calling job below must itself grant every scope the callee's jobs request: +# actions: read (Scorecard's Packaging check), contents: read (checkout), +# security-events: write (SARIF upload), id-token: write (OIDC publication). +# This file died at startup 20/20 times while the job block carried only +# security-events + id-token, which left actions and contents at `none` (#168). +permissions: + contents: read jobs: - analysis: + scorecard: permissions: actions: read contents: read security-events: write id-token: write - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4 - secrets: inherit + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@0f13f51fafe9d2b670252aa2a18993223bffdece