Skip to content

ci: Add OpenSSF Scorecard analysis - #106

Merged
BenWestgate merged 1 commit into
masterfrom
claude/magical-cray-zegjrn
Oct 2, 2026
Merged

BenWestgate merged 1 commit into
masterfrom
claude/magical-cray-zegjrn

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

What

Add .github/workflows/scorecard.yml, which runs OpenSSF Scorecard and uploads its SARIF results to code scanning.

  • Triggers: pushes to master, branch-protection changes, and weekly (Monday 04:29 UTC).
  • Permissions: contents: read at the top level. The job adds only security-events: write (SARIF upload) and id-token: write (publishing to the public Scorecard API).
  • Pinning: every action is pinned to a full commit SHA, as in the existing workflows. checkout reuses the repo's current v4.3.1 pin.

Why

Scorecard checks the repository's supply-chain posture: pinned actions, token permissions, branch protection and signed releases. That matters for a library that handles seeds, and it complements CodeQL, which scans the code itself.

Notes

Scorecard runs only on the default branch, so it takes effect once this pull request is merged into master. Early results will probably flag unsigned commits and branch-protection gaps until the new rulesets are complete.

Validation: the workflow YAML parses, and git diff --check is clean.

AI-written (Claude); requires responsible-human review per docs/developer/AI_POLICY.md.

🤖 Generated with Claude Code

https://claude.ai/code/session_013gZvwvuocM7a7Ut4kiBFHw


Generated by Claude Code

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@BenWestgate
BenWestgate marked this pull request as ready for review October 2, 2026 21:14
Run OpenSSF Scorecard on pushes to master, branch protection changes and a weekly schedule, and upload its SARIF results to code scanning. It reports supply-chain posture this repository cares about: pinned actions, token permissions, branch protection and signed releases.

Actions are pinned to full commit SHAs, as in the existing workflows. Permissions are read-only except the job security-events permission for SARIF upload and id-token permission for publishing results to the public Scorecard API.

Scorecard runs only on the default branch, so this takes effect once this pull request is merged into master.

Claude-Session: https://claude.ai/code/session_013gZvwvuocM7a7Ut4kiBFHw
@BenWestgate
BenWestgate force-pushed the claude/magical-cray-zegjrn branch from bccf047 to 13924ea Compare October 2, 2026 21:30
@BenWestgate
BenWestgate changed the base branch from reviewability-v1 to master October 2, 2026 21:30

Copy link
Copy Markdown
Owner Author

build (3.13) fails here on head 13924ea, but this PR didn't cause it. On Python 3.13, pip can't build coincurve (pulled in via bip32): "Use build.verbose instead of cmake.verbose for scikit-build-core >= 0.10". master has the same failure, and this PR changes only .github/workflows/scorecard.yml. build (3.11) was cancelled by fail-fast; 3.10 and 3.12 pass. There's no fix to port into this PR: v1 drops that dependency.


Generated by Claude Code

@BenWestgate
BenWestgate merged commit 8ab3bae into master Oct 2, 2026
7 of 9 checks passed
@BenWestgate
BenWestgate deleted the claude/magical-cray-zegjrn branch October 2, 2026 21:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants