Skip to content

Fix scorecard workflow permissions#86

Merged
nosborn merged 1 commit intomasterfrom
scorecard-permissions
Jun 12, 2025
Merged

Fix scorecard workflow permissions#86
nosborn merged 1 commit intomasterfrom
scorecard-permissions

Conversation

@nosborn
Copy link
Copy Markdown
Owner

@nosborn nosborn commented Jun 12, 2025

No description provided.

Copilot AI review requested due to automatic review settings June 12, 2025 05:57
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the OpenSSF Scorecard GitHub Actions workflow to comply with the action’s workflow-level permission restrictions.

  • Adds a comment linking to the OSSF Scorecard restrictions documentation
  • Removes workflow-level write permissions
  • Moves id-token: write and security-events: write permissions into the analysis job

@nosborn nosborn merged commit d6d4d28 into master Jun 12, 2025
4 checks passed
@nosborn nosborn deleted the scorecard-permissions branch June 12, 2025 05:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants