Skip to content

ci(scorecard): wire SCORECARD_TOKEN for Branch-Protection check#689

Merged
blove merged 1 commit into
mainfrom
blove/scorecard-token
Jun 18, 2026
Merged

ci(scorecard): wire SCORECARD_TOKEN for Branch-Protection check#689
blove merged 1 commit into
mainfrom
blove/scorecard-token

Conversation

@blove

@blove blove commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Passes repo_token: ${{ secrets.SCORECARD_TOKEN }} to the OSSF Scorecard action so it can read branch-protection settings (the default GITHUB_TOKEN cannot). Resolves the currently-inconclusive Branch-Protection check, raising the Scorecard aggregate.

Requires a repo secret SCORECARD_TOKEN — a fine-grained PAT with Administration: read-only (+ Contents/Metadata read) on this repo. If the secret is unset, the action falls back gracefully and the check stays inconclusive (no failure).

Test Plan

  • CI green
  • After secret is added + next Scorecard run: Branch-Protection scored (not inconclusive)

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@blove blove enabled auto-merge (squash) June 18, 2026 20:31
@vercel

vercel Bot commented Jun 18, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
threadplane Ready Ready Preview, Comment Jun 18, 2026 8:34pm

Request Review

@blove blove merged commit 4bae73b into main Jun 18, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant