Skip to content

fix(ci): make OSSF Scorecard caller valid (perms / drop timeout-minutes) - #56

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/scorecard-caller-startup
Jul 30, 2026
Merged

fix(ci): make OSSF Scorecard caller valid (perms / drop timeout-minutes)#56
hyperpolymath merged 2 commits into
mainfrom
fix/scorecard-caller-startup

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Reusable scorecard caller failed at startup: needed security-events+id-token (reusable perms capped to caller grant) and/or an illegal timeout-minutes on the uses: job. Verified with actionlint. Pin preserved.

Description

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Refactoring (no functional changes)
  • Performance improvement

Related Issues

Checklist

  • My code follows the project's language policy (ReScript, Deno, no TypeScript/npm)
  • I have added SPDX headers to new files
  • I have updated the documentation accordingly
  • I have added tests that prove my fix is effective or my feature works
  • New and existing unit tests pass locally
  • I have run deno fmt and deno lint on my changes

Ecological & Economic Considerations

  • This change improves code efficiency
  • This change has been reviewed for energy patterns
  • This change maintains or improves the project's sustainability

Screenshots (if applicable)

Additional Notes

Reusable scorecard caller failed at startup: needed security-events+id-token
(reusable perms capped to caller grant) and/or an illegal timeout-minutes on the
uses: job. Verified with actionlint. Pin preserved.
@gitar-bot

gitar-bot Bot commented Jul 29, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review ✅ Approved

Updates the OSSF Scorecard workflow configuration by adding required security permissions and removing the invalid timeout setting. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot

gitar-bot Bot commented Jul 29, 2026

Copy link
Copy Markdown

⚠️ Gitar auto-approved this PR but could not enable auto-merge: auto-merge is disabled for this repository — enable "Allow auto-merge" in the repository settings.

gitar-bot[bot]
gitar-bot Bot previously approved these changes Jul 29, 2026

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Jul 29, 2026
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit 2401a79 into main Jul 30, 2026
@hyperpolymath
hyperpolymath deleted the fix/scorecard-caller-startup branch July 30, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant