chore(ci): make Scorecard periodic, not per-push - #173
Merged
Conversation
Scorecard measures the REPOSITORY's supply-chain posture, not the change under review. The estate's signal-discipline standard puts repository-level measurements in the PERIODIC tier: on a schedule against the default branch, feeding one dashboard — not on every event. Measured across 303 scorecard workflows before this sweep: 199 push, schedule, workflow_dispatch 93 branch_protection_rule, schedule, push 1 push, pull_request, schedule, workflow_dispatch 1 schedule, workflow_dispatch <- the target shape So roughly 292 repositories ran a full posture scan on EVERY push to the default branch. That is pure cost: a supply-chain score cannot meaningfully change between two consecutive merges, and it never gated anything. WHAT IS DELIBERATELY KEPT: schedule the point of the tier workflow_dispatch manual re-run when one is actually wanted branch_protection_rule event-driven re-measurement of precisely what Scorecard scores. It fires on a settings change, not per pull request, so it does not violate the PERIODIC rule — and it keeps the score honest after exactly the change most likely to alter it. Only `push` and `pull_request` are removed. `pull_request` existed in one repository and was the genuine violation; `push` was the cost. Related, and the reason this matters beyond minutes: Scorecard was ALSO required as a `code_scanning` tool in 78 repositories at alertsThreshold=all, while producing code-scanning results in essentially none — because it does not emit per-commit SARIF. That made it an estate-wide merge blocker asking to do something it does not do. Those requirements have been removed separately. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
This comment has been minimized.
This comment has been minimized.
hyperpolymath
disabled auto-merge
August 7, 2026 14:52
Uh oh!
There was an error while loading. Please reload this page.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Makes the OpenSSF Scorecard workflow periodic by dropping its
push(and, in one repository,pull_request) trigger.schedule,workflow_dispatchandbranch_protection_ruleare all kept.Why. Scorecard measures the repository's supply-chain posture, not the change under review. That is the
📅 PERIODIC:tier in the estate's signal-discipline standard: on a schedule against the default branch, feeding a dashboard — not on every event. It cannot meaningfully pass or fail a diff.Measured across 303 scorecard workflows before this sweep:
So ~292 repositories ran a full posture scan on every push to the default branch. That is pure cost: the score cannot meaningfully change between two consecutive merges.
Deliberately kept:
branch_protection_rule. It fires on a settings change — not per pull request — so it does not violate the PERIODIC rule, and it re-measures precisely what Scorecard scores after exactly the change most likely to alter it.🤖 Generated with Claude Code