Skip to content

Fix Scorecard SARIF publication#3

Merged
krotname merged 1 commit into
masterfrom
feature/scorecard-action-sarif-20260621
Jun 21, 2026
Merged

Fix Scorecard SARIF publication#3
krotname merged 1 commit into
masterfrom
feature/scorecard-action-sarif-20260621

Conversation

@krotname

Copy link
Copy Markdown
Owner

Summary

  • use pinned ossf/scorecard-action for SARIF output
  • grant OIDC permission required by publish_results
  • upload Scorecard SARIF to Code Scanning

@codecov

codecov Bot commented Jun 21, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3fd32ff7d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

--output="scorecard-results.sarif" \
--show-details
- name: Run Scorecard
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Pin the Scorecard container image too

Using a commit SHA here does not pin the code that actually runs: the action metadata at this revision declares image: docker://ghcr.io/ossf/scorecard-action:v2.4.3, so GitHub pulls a mutable container tag on each run. This regresses from the previous CLI download with a checked SHA256, and because the step now has id-token: write and security-events: write, a retagged or compromised image would run with those privileges before SARIF upload; keep the checksum-verified CLI path or invoke a digest-pinned container instead.

Useful? React with 👍 / 👎.

@krotname krotname merged commit 277d9b3 into master Jun 21, 2026
21 of 22 checks passed
@krotname krotname deleted the feature/scorecard-action-sarif-20260621 branch June 21, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant