Skip to content

ci: guard scorecard behind SCORECARD_ENABLED repo var - #628

Closed
arcaven wants to merge 3 commits into
developfrom
ci/scorecard-guard
Closed

arcaven wants to merge 3 commits into
developfrom
ci/scorecard-guard

Conversation

@arcaven

@arcaven arcaven commented Jul 17, 2026

Copy link
Copy Markdown
Collaborator

Makes Scorecard analysis opt-in: the job runs only when the repo variable SCORECARD_ENABLED is set to true — the same opt-in pattern already used for SIGNING_ENABLED. No var, no run. Forks and clones stay quiet by default; enable per repo by adding the variable.

@arcaven
arcaven requested a review from Zious11 as a code owner July 17, 2026 17:00
Zious11 added a commit to Zious11/wirerust that referenced this pull request Jul 19, 2026
…414)

Adds the OSSF Scorecard workflow (same shape as jira-cli's
`scorecards.yml`, see Zious11/jira-cli#628) with the analysis job opt-in
from day one: it runs only when the repo variable `SCORECARD_ENABLED` is
set to `true` — the same opt-in pattern already used for
`SIGNING_ENABLED`. No var, no run. Forks and clones stay quiet by
default; enable per repo by adding the variable.

Co-authored-by: Jared Richards <jaredbrichards@gmail.com>
Zious11
Zious11 previously approved these changes Jul 21, 2026
@arcavenai

Copy link
Copy Markdown
Contributor

Diagnosed the two failing checks — unrelated to this PR's change (the diff is 4 lines in scorecards.yml; the failure is in Spec Guards' BC citation check):

Fix: update the branch against develop (the GitHub "Update branch" button suffices — the branch touches only scorecards.yml, so it's conflict-free) and let checks re-run. This account doesn't have write access to push the prepared merge, so flagging for someone who does.

@arcavenai

Copy link
Copy Markdown
Contributor

To make the fix copy-paste executable (this account can't push to this branch): no file content changes are needed — the remedy is purely a branch refresh, since the DEAD citations name files that exist on current develop (e33624c…c28ae94, the four S-576 attachment PRs) but not in this branch's stale merge ref.

Either click Update branch on this PR, or:

git fetch origin develop ci/scorecard-guard
git checkout ci/scorecard-guard
git merge origin/develop        # conflict-free — this branch touches only .github/workflows/scorecards.yml
git push origin ci/scorecard-guard

Verified locally on exactly that merge: mounted factory-artifacts at .factory/ and ran bash scripts/check-bc-citation-symbols.sh → Check passed: 354 citations checked (exit 0), and the PR's own diff remains the 4-line SCORECARD_ENABLED gate.

@arcaven
arcaven requested a review from Zious11 July 23, 2026 00:57
Scorecard analysis is now opt-in: the job runs only when the repo
variable SCORECARD_ENABLED is set to true (same opt-in pattern as
SIGNING_ENABLED). No var, no run — forks and clones stay quiet by
default.
@arcaven
arcaven force-pushed the ci/scorecard-guard branch from 7584b52 to 2d5ae74 Compare August 4, 2026 22:57
@Zious11

Zious11 commented Aug 13, 2026

Copy link
Copy Markdown
Owner

Thanks — this is the behavior I want: Scorecard disabled by default, enabled per-repo via SCORECARD_ENABLED. I'm keeping the opt-in polarity exactly as you have it (if: vars.SCORECARD_ENABLED == 'true') — no flip to a _DISABLED variable. The canonical repo will intentionally leave it off unless the variable is set, which is the intended outcome.

Design and scope look good — the placement matches the existing SIGNING_ENABLED/ATTESTATIONS_ENABLED gate pattern, and there's no security concern (the change only adds an opt-in gate). Two things before it merges:

Please add

  • Document the new gate, same as the other *_ENABLED gates:

    • docs/specs/fork-friendly-release-ops.md — add a SCORECARD_ENABLED row to the repository-variables table.
    • CLAUDE.md — add it to the "Release-ops repo-variable gates" bullet.

    (This repo documents each new vars.* gate in the same commit as the workflow change.)

Housekeeping

  • Rebase onto develop and re-run CI — the branch is a few weeks stale. The if: insertion point is untouched by the recent scorecard-action/upload-sarif bumps, so it should be a clean rebase; I just want a fresh green against current develop.

Thanks for tightening this up.

The scorecard guard added a repository-variable gate but the two places
that list those gates did not mention it. Add the row to
docs/specs/fork-friendly-release-ops.md and the entry in CLAUDE.md's
gates paragraph, matching the shape of the existing variables.
@arcaven

arcaven commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator Author

Caught up and the two doc asks are in, so this should be mergeable as-is once CI runs.

  • Merged develop in at cfe1ded (a40efbb, no conflicts).
  • bf5862f adds the SCORECARD_ENABLED row to docs/specs/fork-friendly-release-ops.md and the entry in CLAUDE.md's repository-variables paragraph, in the shape of the existing gates.

Against develop the PR is now 3 files, +6/-1 (gh api repos/Zious11/jira-cli/compare/cfe1dedc...bf5862f2): the 4 guard lines in scorecards.yml plus the two doc lines. Ordinary merge commit rather than a rebase, so the approved commit is unchanged.

Zious11 added a commit that referenced this pull request Sep 17, 2026
…endency posture clean, 2 transitional deny.toml skips landed

Sweeps run: dependency-audit (CLEAN, 0 RUSTSEC / 359 deps), doc-drift
(7 findings fixed), pattern-consistency + spec-coherence (4 findings
fixed, 3 known/backlogged), tech-debt-register (no overdue items).
Sweeps 4/5 (holdout-freshness, perf-regression) skipped by human
decision; 6/9 (DTU, accessibility) N/A for this CLI-only product.

12 PRs squash-merged to develop (01e278f->0496834d): #825 (docs),
#826/#830 (deny.toml transitional skips for syn 2/3 and
windows_i686_gnullvm 0.53, each with a documented cargo-tree removal
trigger), plus 9 Dependabot bumps (#821/#820/#829/#738/#730/#729/
#688/#828/#727). Final cargo deny check on merged develop: clean.

6 process-gap findings + 2 standing items logged to
OPEN-STANDING-ITEMS.md (4 confirmed recurrences of prior hook/
sub-agent-stall defects; 2 new operational learnings on Dependabot
handling and auto-mode classifier non-determinism). #827/#628 flagged
as a duplicate PR pair; #574 left for separate human review.

STATE.md v4.50->v4.51: pipeline returns to PAUSED, no cycle ACTIVE,
008-011 remain PARKED. Full report: maintenance/sweep-report-2026-09-16.md
@Zious11

Zious11 commented Sep 17, 2026

Copy link
Copy Markdown
Owner

Accepterd in the other PR #827. Closing this one

@Zious11 Zious11 closed this Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants