Skip to content

ci: move scorecard write permissions to job level#7

Merged
cwaits6 merged 1 commit intomainfrom
ci/scorecard-permissions
Mar 19, 2026
Merged

ci: move scorecard write permissions to job level#7
cwaits6 merged 1 commit intomainfrom
ci/scorecard-permissions

Conversation

@cwaits6
Copy link
Owner

@cwaits6 cwaits6 commented Mar 19, 2026

Summary

  • The OpenSSF scorecard webapp rejects results from workflows with top-level write permissions
  • Moves security-events: write and id-token: write from the workflow-level permissions block to the job level
  • Sets top-level permissions to read-all

Test plan

  • Merge and verify scorecard passes in a consuming repo (e.g. apk-datasource)

The OpenSSF scorecard webapp rejects results from workflows with
top-level write permissions. Moving security-events and id-token
write permissions to the job level satisfies the verification check.
@cwaits6 cwaits6 merged commit 1bdc765 into main Mar 19, 2026
@cwaits6 cwaits6 deleted the ci/scorecard-permissions branch March 19, 2026 05:08
@github-actions
Copy link

🎉 This PR is included in version 1.5.2 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant