chore(ci): make Scorecard periodic, not per-push - #177
Conversation
Scorecard measures the REPOSITORY's supply-chain posture, not the change under
review. The estate's signal-discipline standard puts repository-level
measurements in the PERIODIC tier: on a schedule against the default branch,
feeding one dashboard — not on every event.
Measured across 303 scorecard workflows before this sweep:
199 push, schedule, workflow_dispatch
93 branch_protection_rule, schedule, push
1 push, pull_request, schedule, workflow_dispatch
1 schedule, workflow_dispatch <- the target shape
So roughly 292 repositories ran a full posture scan on EVERY push to the
default branch. That is pure cost: a supply-chain score cannot meaningfully
change between two consecutive merges, and it never gated anything.
WHAT IS DELIBERATELY KEPT:
schedule the point of the tier
workflow_dispatch manual re-run when one is actually wanted
branch_protection_rule event-driven re-measurement of precisely what
Scorecard scores. It fires on a settings change, not
per pull request, so it does not violate the PERIODIC
rule — and it keeps the score honest after exactly
the change most likely to alter it.
Only `push` and `pull_request` are removed. `pull_request` existed in one
repository and was the genuine violation; `push` was the cost.
Related, and the reason this matters beyond minutes: Scorecard was ALSO
required as a `code_scanning` tool in 78 repositories at alertsThreshold=all,
while producing code-scanning results in essentially none — because it does not
emit per-commit SARIF. That made it an estate-wide merge blocker asking to do
something it does not do. Those requirements have been removed separately.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedUpdates the OpenSSF Scorecard workflow to run periodically on a schedule, branch protection rule, and manual dispatch rather than on every push. No issues found.
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Important Your trial ends in 4 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more. Was this helpful? React with 👍 / 👎 | Gitar |
🔍 Hypatia Security ScanFindings: 39 issues detected
View findings[
{
"reason": "Agda postulate assumes without proof -- potential soundness hole (1 occurrences, CWE-704)",
"type": "agda_postulate",
"file": "/home/runner/work/valence-shell/valence-shell/proofs/agda/FilesystemModel.agda",
"action": "flag",
"rule_module": "code_safety",
"severity": "critical"
},
{
"reason": "believe_me undermines formal verification (2 occurrences, CWE-704)",
"type": "believe_me",
"file": "/home/runner/work/valence-shell/valence-shell/proofs/idris2/src/Filesystem/Axioms.idr",
"action": "flag",
"rule_module": "code_safety",
"severity": "critical"
},
{
"reason": "JSON decode without validation (1 occurrences, CWE-20)",
"type": "json_decode_no_validation",
"file": "/home/runner/work/valence-shell/valence-shell/impl/mcp/src/Server.res",
"action": "flag",
"rule_module": "code_safety",
"severity": "critical"
},
{
"reason": "Obj.magic bypassing type safety (2 occurrences, CWE-704)",
"type": "obj_magic",
"file": "/home/runner/work/valence-shell/valence-shell/impl/mcp/src/bindings/Mcp.res",
"action": "flag",
"rule_module": "code_safety",
"severity": "high"
},
{
"reason": "expect() in hot path (1 occurrences, CWE-754)",
"type": "expect_in_hot_path",
"file": "/home/runner/work/valence-shell/valence-shell/impl/rust-cli/src/executable.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "medium"
},
{
"reason": "expect() in hot path (1 occurrences, CWE-754)",
"type": "expect_in_hot_path",
"file": "/home/runner/work/valence-shell/valence-shell/impl/rust-cli/src/arith.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "medium"
},
{
"reason": "unwrap() without prior check -- DoS via panic (1 occurrences, CWE-754)",
"type": "unwrap_without_check",
"file": "/home/runner/work/valence-shell/valence-shell/impl/rust-cli/src/test_command.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "high"
},
{
"reason": "expect() in hot path (1 occurrences, CWE-754)",
"type": "expect_in_hot_path",
"file": "/home/runner/work/valence-shell/valence-shell/impl/rust-cli/src/glob.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "medium"
},
{
"reason": "unsafe block -- requires SAFETY comment (2 occurrences, CWE-676)",
"type": "unsafe_block",
"file": "/home/runner/work/valence-shell/valence-shell/impl/rust-cli/src/process_sub.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "medium"
},
{
"reason": "as_ptr exposes raw pointer that may dangle or alias unsafely (2 occurrences, CWE-676)",
"type": "as_ptr",
"file": "/home/runner/work/valence-shell/valence-shell/impl/rust-cli/src/process_sub.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
Makes the OpenSSF Scorecard workflow periodic by dropping its
push(and, in one repository,pull_request) trigger.schedule,workflow_dispatchandbranch_protection_ruleare all kept.Why. Scorecard measures the repository's supply-chain posture, not the change under review. That is the
📅 PERIODIC:tier in the estate's signal-discipline standard: on a schedule against the default branch, feeding a dashboard — not on every event. It cannot meaningfully pass or fail a diff.Measured across 303 scorecard workflows before this sweep:
So ~292 repositories ran a full posture scan on every push to the default branch. That is pure cost: the score cannot meaningfully change between two consecutive merges.
Deliberately kept:
branch_protection_rule. It fires on a settings change — not per pull request — so it does not violate the PERIODIC rule, and it re-measures precisely what Scorecard scores after exactly the change most likely to alter it.🤖 Generated with Claude Code