Skip to content

chore(security): add OpenSSF Scorecard workflow - #419

Open
nirmal-joishi-a0 wants to merge 1 commit into
masterfrom
security/add-scorecard
Open

nirmal-joishi-a0 wants to merge 1 commit into
masterfrom
security/add-scorecard

Conversation

@nirmal-joishi-a0

Copy link
Copy Markdown

✏️ Changes

This pull request adds a security hardening workflow. No functional changes are introduced.

🚧 Automated PR — verify before merging. It runs on this PR, so confirm it actually triggers and passes, and that a green result is not masking a skipped or silently-ignored scan. Do not merge solely because checks appear green.

If the run fails for anything specific to this repo — a missing secret, environment setup, or other config only this repo needs (which we, as external authors, have no visibility into) — fixing it before merging is the repo owner's responsibility.

OpenSSF Scorecard

This PR adds .github/workflows/scorecard.yml. It calls ossf/scorecard-action directly (SHA-pinned to v2.4.3) — no composite action wrapper, no cross-org dependency. Results are uploaded to the Code Scanning dashboard via github/codeql-action/upload-sarif.

⚠️ Before merging, review the added .github/workflows/scorecard.yml and make the changes described below, plus any other adjustments your CI environment requires.

🧪 Smoke test only on this PR — not authoritative. The pull_request trigger runs this workflow on a real runner from this PR, giving you a pre-merge smoke run. workflow_dispatch does not run from this PR — GitHub offers manual dispatch only for a workflow already on the default branch, so it becomes available for manual re-runs only after this PR merges. OSSF officially documents both triggers as experimental (scorecard-action README: "The pull_request and workflow_dispatch triggers are experimental"); the supported triggers are push and schedule on the default branch. Treat a green pull_request run here only as a signal that the workflow ran — it is considered fully validated only after merge to the default branch, where it runs on the supported push and weekly schedule events. Code Scanning (SARIF) upload is skipped only on fork PRs (their token can't write it); it runs on same-repo PRs and on push/schedule after merge.

If the workflow fails specifically on the experimental pull_request trigger, you may remove both the pull_request and workflow_dispatch triggers and keep only the supported push and schedule events. In that case there is no PR-time smoke test, so validation happens by merging the PR once and confirming the workflow runs on the resulting push to the default branch.

Placeholders to fill in before merging

Placeholder Description
publish_results: false Default. Set to true to publish results to the public Scorecard API and enable the badge — also requires uncommenting id-token: write in the job permissions. Leave as false to keep results private (the id-token: write line can remain commented out).

🟠 Declining this workflow

This is an organization-enforced security-hardening workflow, so closing this PR is not enough — the tool treats a plain close as a discard and opens a fresh replacement PR on its next run.

To permanently decline this category, a maintainer must close this PR and add one of these labels to it:

Label Use when
remediation: not-required The category is already handled another way for this repo.
remediation: not-applicable The category genuinely does not apply (e.g. there is no manifest to scan for SCA, or no release/build CI to wire the malware scan into).

Applying a label requires write, triage, or admin access, so the label is a trusted maintainer signal. Once a closed PR carries one of these labels, the tool respects the decline and will not reopen a replacement.

🔮 Type of Change

  • Standard

🔗 References

This change applies a standard automated security-scanning workflow as part of routine repository hardening.

  • I explained why this change is needed.

📖 Documentation

No user-facing changes have been introduced.

  • I reflected this change in the (internal and/or user-facing) documentation, or added an explanation for why no documentation update is needed.

🎯 Testing

⚠️ This workflow runs on this PR. Before merging, confirm that run triggers and passes, and that a green result is not masking a skipped or silently-ignored scan.

  • The PR run has been verified green in this repository's CI (not a skipped/empty result).

🚀 Deployment

  • This change can support multiple releases of the code serving traffic at the same time.

🔥 Rollback

Reverting this PR removes the added workflow file — no further action required.

  • I explained what the rollback for this change will look like.

Supersedes #417, a previous remediation PR for this workflow that was closed. This workflow is organization-enforced, so a fresh PR was opened to replace it.

@nirmal-joishi-a0
nirmal-joishi-a0 requested a review from a team as a code owner October 5, 2026 18:24
@nirmal-joishi-a0

Copy link
Copy Markdown
Author

The previous remediation PR for this workflow was closed. This is an organization-enforced, mandatory security-hardening workflow, so we've opened a new PR to replace the discarded one. Please review the changes and update them if needed. Note: this workflow is untested in this repo — confirm it triggers and passes before merging; do not merge on a green result alone. To permanently decline this workflow, closing this PR is not enough (a fresh replacement will be opened): close it AND add one of these labels — remediation: not-required (handled another way) or remediation: not-applicable (does not apply here). Adding a label needs write/triage/admin access, so it is treated as a maintainer's decision and no replacement will be opened.

@nirmal-joishi-a0

Copy link
Copy Markdown
Author

@auth0/project-dx-sdks-engineer-codeowner please review the files in the PR. This automated security-hardening workflow is untested in this repo — before merging, confirm it triggers and passes (and is not silently ignoring failures); do not merge on a green result alone.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@nirmal-joishi-a0

Copy link
Copy Markdown
Author

An internal service ticket has been filed for the owning team to review and merge this PR.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants