From aafdab5a4ce7a66d99236a6782f6f267352f1bd4 Mon Sep 17 00:00:00 2001 From: Thomas Sprayberry <263217947+askalf@users.noreply.github.com> Date: Fri, 25 Sep 2026 21:59:46 -0400 Subject: [PATCH] ci: scorecard comment says what the job token reads, not -1 --- .github/workflows/scorecard.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 5d8b082..c35622a 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -33,11 +33,11 @@ jobs: with: results_file: results.sarif results_format: sarif - # The default GITHUB_TOKEN can't read branch-protection settings, so the - # Branch-Protection check errors out (-1). A fine-grained PAT with - # `administration: read` + `metadata: read` (repo secret SCORECARD_TOKEN) - # lets it read them; falls back to the default token if the secret is - # unset (all other checks still run). + # Branch-Protection scores from what the job token can read: the public + # rules of a public repo (5-8 of 10 here, not the -1 an earlier comment + # claimed). A fine-grained PAT with `administration: read` + `metadata: + # read` in the SCORECARD_TOKEN secret would also read the admin-only + # settings; no repo sets one, so the fallback is the path every run takes. repo_token: ${{ secrets.SCORECARD_TOKEN || github.token }} publish_results: true