Skip to content

chore(ci): make Scorecard periodic, not per-push - #173

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/scorecard-periodic
Aug 7, 2026
Merged

chore(ci): make Scorecard periodic, not per-push#173
hyperpolymath merged 1 commit into
mainfrom
chore/scorecard-periodic

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Makes the OpenSSF Scorecard workflow periodic by dropping its push (and, in one repository, pull_request) trigger. schedule, workflow_dispatch and branch_protection_rule are all kept.

Why. Scorecard measures the repository's supply-chain posture, not the change under review. That is the 📅 PERIODIC: tier in the estate's signal-discipline standard: on a schedule against the default branch, feeding a dashboard — not on every event. It cannot meaningfully pass or fail a diff.

Measured across 303 scorecard workflows before this sweep:

199 push, schedule, workflow_dispatch
93 branch_protection_rule, schedule, push
1 push, pull_request, schedule, workflow_dispatch
1 schedule, workflow_dispatch <- the target shape

So ~292 repositories ran a full posture scan on every push to the default branch. That is pure cost: the score cannot meaningfully change between two consecutive merges.

Deliberately kept:branch_protection_rule. It fires on a settings change — not per pull request — so it does not violate the PERIODIC rule, and it re-measures precisely what Scorecard scores after exactly the change most likely to alter it.

🤖 Generated with Claude Code

Scorecard measures the REPOSITORY's supply-chain posture, not the change under
review. The estate's signal-discipline standard puts repository-level
measurements in the PERIODIC tier: on a schedule against the default branch,
feeding one dashboard — not on every event.
Measured across 303 scorecard workflows before this sweep:
199 push, schedule, workflow_dispatch
93 branch_protection_rule, schedule, push
1 push, pull_request, schedule, workflow_dispatch
1 schedule, workflow_dispatch <- the target shape
So roughly 292 repositories ran a full posture scan on EVERY push to the
default branch. That is pure cost: a supply-chain score cannot meaningfully
change between two consecutive merges, and it never gated anything.
WHAT IS DELIBERATELY KEPT:
schedule the point of the tier
workflow_dispatch manual re-run when one is actually wanted
branch_protection_rule event-driven re-measurement of precisely what
Scorecard scores. It fires on a settings change, not
per pull request, so it does not violate the PERIODIC
rule — and it keeps the score honest after exactly
the change most likely to alter it.
Only `push` and `pull_request` are removed. `pull_request` existed in one
repository and was the genuine violation; `push` was the cost.
Related, and the reason this matters beyond minutes: Scorecard was ALSO
required as a `code_scanning` tool in 78 repositories at alertsThreshold=all,
while producing code-scanning results in essentially none — because it does not
emit per-commit SARIF. That made it an estate-wide merge blocker asking to do
something it does not do. Those requirements have been removed separately.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@gitar-bot

This comment has been minimized.

@gitar-bot
gitar-botBot enabled auto-merge (squash) August 6, 2026 11:51

@gitar-botgitar-botBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-botgitar-botBot added the gitar-approved Added by Gitar label Aug 6, 2026
@hyperpolymath
hyperpolymath merged commit 043a380 into mainAug 7, 2026
1 check passed
@hyperpolymath
hyperpolymath deleted the chore/scorecard-periodic branch August 7, 2026 14:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approvedAdded by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@hyperpolymath