Conversation
…414) Adds the OSSF Scorecard workflow (same shape as jira-cli's `scorecards.yml`, see Zious11/jira-cli#628) with the analysis job opt-in from day one: it runs only when the repo variable `SCORECARD_ENABLED` is set to `true` — the same opt-in pattern already used for `SIGNING_ENABLED`. No var, no run. Forks and clones stay quiet by default; enable per repo by adding the variable. Co-authored-by: Jared Richards <jaredbrichards@gmail.com>
|
Diagnosed the two failing checks — unrelated to this PR's change (the diff is 4 lines in
Fix: update the branch against |
|
To make the fix copy-paste executable (this account can't push to this branch): no file content changes are needed — the remedy is purely a branch refresh, since the DEAD citations name files that exist on current Either click Update branch on this PR, or: git fetch origin develop ci/scorecard-guard
git checkout ci/scorecard-guard
git merge origin/develop # conflict-free — this branch touches only .github/workflows/scorecards.yml
git push origin ci/scorecard-guardVerified locally on exactly that merge: mounted |
Scorecard analysis is now opt-in: the job runs only when the repo variable SCORECARD_ENABLED is set to true (same opt-in pattern as SIGNING_ENABLED). No var, no run — forks and clones stay quiet by default.
7584b52 to
2d5ae74
Compare
|
Thanks — this is the behavior I want: Scorecard disabled by default, enabled per-repo via Design and scope look good — the placement matches the existing Please add
Housekeeping
Thanks for tightening this up. |
The scorecard guard added a repository-variable gate but the two places that list those gates did not mention it. Add the row to docs/specs/fork-friendly-release-ops.md and the entry in CLAUDE.md's gates paragraph, matching the shape of the existing variables.
|
Caught up and the two doc asks are in, so this should be mergeable as-is once CI runs.
Against develop the PR is now 3 files, +6/-1 ( |
…endency posture clean, 2 transitional deny.toml skips landed Sweeps run: dependency-audit (CLEAN, 0 RUSTSEC / 359 deps), doc-drift (7 findings fixed), pattern-consistency + spec-coherence (4 findings fixed, 3 known/backlogged), tech-debt-register (no overdue items). Sweeps 4/5 (holdout-freshness, perf-regression) skipped by human decision; 6/9 (DTU, accessibility) N/A for this CLI-only product. 12 PRs squash-merged to develop (01e278f->0496834d): #825 (docs), #826/#830 (deny.toml transitional skips for syn 2/3 and windows_i686_gnullvm 0.53, each with a documented cargo-tree removal trigger), plus 9 Dependabot bumps (#821/#820/#829/#738/#730/#729/ #688/#828/#727). Final cargo deny check on merged develop: clean. 6 process-gap findings + 2 standing items logged to OPEN-STANDING-ITEMS.md (4 confirmed recurrences of prior hook/ sub-agent-stall defects; 2 new operational learnings on Dependabot handling and auto-mode classifier non-determinism). #827/#628 flagged as a duplicate PR pair; #574 left for separate human review. STATE.md v4.50->v4.51: pipeline returns to PAUSED, no cycle ACTIVE, 008-011 remain PARKED. Full report: maintenance/sweep-report-2026-09-16.md
|
Accepterd in the other PR #827. Closing this one |
Makes Scorecard analysis opt-in: the job runs only when the repo variable
SCORECARD_ENABLEDis set totrue— the same opt-in pattern already used forSIGNING_ENABLED. No var, no run. Forks and clones stay quiet by default; enable per repo by adding the variable.