Skip to content

chore(ci): make Scorecard periodic, not per-push - #42

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/scorecard-periodic
Aug 6, 2026
Merged

chore(ci): make Scorecard periodic, not per-push#42
hyperpolymath merged 1 commit into
mainfrom
chore/scorecard-periodic

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Makes the OpenSSF Scorecard workflow periodic by dropping its push (and, in one repository, pull_request) trigger. schedule, workflow_dispatch and branch_protection_rule are all kept.

Why. Scorecard measures the repository's supply-chain posture, not the change under review. That is the 📅 PERIODIC: tier in the estate's signal-discipline standard: on a schedule against the default branch, feeding a dashboard — not on every event. It cannot meaningfully pass or fail a diff.

Measured across 303 scorecard workflows before this sweep:

199 push, schedule, workflow_dispatch
93 branch_protection_rule, schedule, push
1 push, pull_request, schedule, workflow_dispatch
1 schedule, workflow_dispatch <- the target shape

So ~292 repositories ran a full posture scan on every push to the default branch. That is pure cost: the score cannot meaningfully change between two consecutive merges.

Deliberately kept:branch_protection_rule. It fires on a settings change — not per pull request — so it does not violate the PERIODIC rule, and it re-measures precisely what Scorecard scores after exactly the change most likely to alter it.

🤖 Generated with Claude Code

Scorecard measures the REPOSITORY's supply-chain posture, not the change under
review. The estate's signal-discipline standard puts repository-level
measurements in the PERIODIC tier: on a schedule against the default branch,
feeding one dashboard — not on every event.
Measured across 303 scorecard workflows before this sweep:
199 push, schedule, workflow_dispatch
93 branch_protection_rule, schedule, push
1 push, pull_request, schedule, workflow_dispatch
1 schedule, workflow_dispatch <- the target shape
So roughly 292 repositories ran a full posture scan on EVERY push to the
default branch. That is pure cost: a supply-chain score cannot meaningfully
change between two consecutive merges, and it never gated anything.
WHAT IS DELIBERATELY KEPT:
schedule the point of the tier
workflow_dispatch manual re-run when one is actually wanted
branch_protection_rule event-driven re-measurement of precisely what
Scorecard scores. It fires on a settings change, not
per pull request, so it does not violate the PERIODIC
rule — and it keeps the score honest after exactly
the change most likely to alter it.
Only `push` and `pull_request` are removed. `pull_request` existed in one
repository and was the genuine violation; `push` was the cost.
Related, and the reason this matters beyond minutes: Scorecard was ALSO
required as a `code_scanning` tool in 78 repositories at alertsThreshold=all,
while producing code-scanning results in essentially none — because it does not
emit per-commit SARIF. That made it an estate-wide merge blocker asking to do
something it does not do. Those requirements have been removed separately.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@gitar-bot

gitar-botBot commented Aug 6, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review👍 Approved with suggestions0 resolved / 1 findings

Updates the OpenSSF Scorecard workflow to run periodically via schedule and branch_protection_rule triggers. Consider adding the workflow_dispatch trigger back if manual re-runs are desired, as it was omitted from the final configuration.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

💡 Quality: workflow_dispatch missing despite being 'deliberately kept'

📄 .github/workflows/scorecard.yml:4-7

The commit message lists workflow_dispatch under "WHAT IS DELIBERATELY KEPT" ("manual re-run when one is actually wanted"), but this workflow never had a workflow_dispatch trigger and still doesn't — after this change the triggers are only branch_protection_rule and schedule. As a result there is no way to manually re-run the Scorecard scan, contrary to the stated design. Add workflow_dispatch: to the on: block to match the documented intent.

Add workflow_dispatch to allow manual re-runs as described in the commit message.
on:
branch_protection_rule:
schedule:
- cron: '23 4 * * 1'
workflow_dispatch:
🤖 Prompt for agents
Code Review: Updates the OpenSSF Scorecard workflow to run periodically via schedule and branch_protection_rule triggers. Consider adding the workflow_dispatch trigger back if manual re-runs are desired, as it was omitted from the final configuration.
1. 💡 Quality: workflow_dispatch missing despite being 'deliberately kept'
Files: .github/workflows/scorecard.yml:4-7
The commit message lists `workflow_dispatch` under "WHAT IS DELIBERATELY KEPT" ("manual re-run when one is actually wanted"), but this workflow never had a `workflow_dispatch` trigger and still doesn't — after this change the triggers are only `branch_protection_rule` and `schedule`. As a result there is no way to manually re-run the Scorecard scan, contrary to the stated design. Add `workflow_dispatch:` to the `on:` block to match the documented intent.
Fix (Add workflow_dispatch to allow manual re-runs as described in the commit message.):
on:
branch_protection_rule:
schedule:
- cron: '23 4 * * 1'
workflow_dispatch:
Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose 

Important

Your trial ends in 4 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-botgitar-botBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️This PR is blocked due to unresolved code review findings.

Configure merge blocking · Maintainers can dismiss this review.

@gitar-bot

gitar-botBot commented Aug 6, 2026

Copy link
Copy Markdown

⚠️ Gitar auto-approved this PR but could not enable auto-merge: auto-merge is disabled for this repository — enable "Allow auto-merge" in the repository settings.

@gitar-botgitar-botBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-botgitar-botBot added the gitar-approved Added by Gitar label Aug 6, 2026
@hyperpolymath
hyperpolymath merged commit e39b130 into mainAug 6, 2026
30 of 34 checks passed
@hyperpolymath
hyperpolymath deleted the chore/scorecard-periodic branch August 6, 2026 12:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approvedAdded by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@hyperpolymath