Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update scorecard.yml with token #1603

Merged
merged 3 commits into from
Jan 17, 2024
Merged

Update scorecard.yml with token #1603

merged 3 commits into from
Jan 17, 2024

Conversation

Zeitsperre
Copy link
Collaborator

Pull Request Checklist:

  • This PR addresses an already opened issue (for bug fixes / features)
    • This PR fixes #xyz
  • Tests for the changes have been added (for bug fixes / features)
    • (If applicable) Documentation has been added / updated (for bug fixes / features)
  • CHANGES.rst has been updated (with summary of main changes)
    • Link to issue (:issue:number) and pull request (:pull:number) has been added

What kind of change does this PR introduce?

  • Adds a token that allows OpenSSF Scorecard workflow to see the branch protection rules of xclim.

Does this PR introduce a breaking change?

No.

Other information:

The token (OPENSSF_SCORECARD_TOKEN) has been given the following permissions for repositories xclim, xscen, miranda, figanos, and raven-hydro:

  • Administration: Read-Only
  • Metadata: Read-Only
  • Webhooks: Read-Only

This is set to expire on January 1st, 2025. After this point it will need to be renewed or another person with maintainer access can generate a new one.

See: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md

@Zeitsperre Zeitsperre requested a review from aulemahal January 17, 2024 20:08
@github-actions github-actions bot added the CI Automation and Contiunous Integration label Jan 17, 2024
@github-actions github-actions bot added the approved Approved for additional tests label Jan 17, 2024
@coveralls
Copy link

Coverage Status

coverage: 90.284%. remained the same
when pulling 3f4c927 on openssf-token
into 507bd0b on master.

@Zeitsperre Zeitsperre merged commit 9ac718b into master Jan 17, 2024
16 checks passed
@Zeitsperre Zeitsperre deleted the openssf-token branch January 17, 2024 20:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Approved for additional tests CI Automation and Contiunous Integration
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants