Fix Scorecard SARIF publication#19
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e29cd47163
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| --output="scorecard-results.sarif" \ | ||
| --show-details | ||
| - name: Run Scorecard | ||
| uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3 |
There was a problem hiding this comment.
Preserve dispatch runs on selected branches
Because this workflow still has workflow_dispatch, a maintainer can manually run it against a feature or release branch, but ossf/scorecard-action v2.4.3 rejects any non-PR event whose GITHUB_REF is not the repository default branch with only default branch is supported. The previous CLI path analyzed ${GITHUB_SHA} and produced/uploaded SARIF for those manual branch runs, so this replacement makes that advertised trigger fail before the SARIF and artifact upload steps; either restrict dispatch to the default branch or keep a non-default-branch path that does not use the action's default-branch validation.
Useful? React with 👍 / 👎.
|



Summary