Skip to content

ci: scorecard comment says what the job token reads - #91

Merged
askalf merged 1 commit into
mainfrom
ci/scorecard-comment
Sep 26, 2026
Merged

askalf merged 1 commit into
mainfrom
ci/scorecard-comment

Conversation

@askalf

@askalf askalf commented Sep 26, 2026

Copy link
Copy Markdown
Owner

From the 2026-09-25 audit of every action, item 24: the comment above repo_token says the Branch-Protection check "errors out (-1)" without a SCORECARD_TOKEN secret. It does not: no repo in the estate sets the secret, every run takes the github.token fallback, and Branch-Protection scores 5-8 from the public rules. The comment now says what the token can and cannot read. The expression is unchanged, so a PAT set later still takes precedence.

@sprayberry-redline sprayberry-redline left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review from the Sprayberry Labs fleet code reviewer.

Reviewed by the gating lane (gating review).

Verdict: approve. Comment-only change to the scorecard workflow; the repo_token expression, triggers, permissions and pinned action SHAs are untouched, so there is no behavioural or security change. The new comment text is plain prose with no AI attribution, secrets or generated-sounding filler. One non-blocking note on the wording.

Minor:

  • .github/workflows/scorecard.yml:37: The parenthetical "not the -1 an earlier comment claimed" refers to the comment's own edit history rather than the workflow. Once this merges nobody reading the file can see the earlier comment, so the clause is noise for the next reader; the PR description already records the correction.

@github-actions github-actions Bot added github_actions Pull requests that update GitHub Actions code size/S 10-49 hand-written lines labels Sep 26, 2026
@askalf
askalf enabled auto-merge (squash) September 26, 2026 02:01
@askalf
askalf merged commit 0914805 into main Sep 26, 2026
14 checks passed
@askalf
askalf deleted the ci/scorecard-comment branch September 26, 2026 02:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code size/S 10-49 hand-written lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants