OpenSSF Scorecard Triage And Remediation¶
The Scorecard workflow runs weekly and on pushes to main,
uploading SARIF to GitHub code scanning (publish_results: false, so results stay private to the
repo). Use this runbook to read the findings and decide what to fix.
Where To Read Findings¶
- Security tab → Code scanning, filtered to the
scorecardtool. Each alert maps to one Scorecard check with a 0-10 score and a remediation hint. - Re-run on demand from Actions → OpenSSF Scorecard → Run workflow, or:
Triage Order¶
Score each finding by exploitability, not just the raw number. Work top-down:
- Critical / high-risk checks first:
Dangerous-Workflow,Token-Permissions,Branch-Protection,Binary-Artifacts. A failingDangerous-Workflowor broadToken-Permissionsis a real, fixable supply-chain risk and should be handled same-day. - Build-integrity checks:
Pinned-Dependencies,Signed-Releases,Vulnerabilities,Dependency-Update-Tool. This repo already pins GitHub Actions by tag/digest, pins Python with hashed lockfiles, signs images with Cosign, and gates on Trivy, so these should stay green; investigate any regression as a pinning or lockfile drift. - Process checks:
Code-Review,Maintained,CI-Tests,Fuzzing,SAST,Security-Policy.SASTis satisfied by the CodeQL workflow;Security-Policyby SECURITY.md.
Remediation Patterns¶
| Failing check | Typical fix in this repo |
|---|---|
Token-Permissions |
Add least-privilege permissions: to the workflow or job; default to contents: read. |
Pinned-Dependencies |
Pin the action to a full-length commit SHA or release tag; regenerate hashed Python locks with pip-compile. |
Dangerous-Workflow |
Remove pull_request_target + untrusted checkout patterns; never interpolate untrusted input into run:. |
Branch-Protection |
Enable required reviews and required status checks on main in repo settings. |
Vulnerabilities |
Bump the offending dependency and regenerate locks; confirm make image-scan is clean. |
Signed-Releases |
Already handled by Cosign signing in ci.yml; confirm the signing step ran. |
Accepting A Finding¶
Some checks (for example Fuzzing, Branch-Protection on a solo-maintained repo) may be
intentionally out of scope. Record the decision and rationale in the pull request that touches the
related area, and dismiss the code-scanning alert with the matching reason so it does not re-surface
as actionable. Do not silence a finding without a written rationale.
Verification¶
After remediation, re-run the workflow and confirm the alert clears in the Security tab. For
pinning or permissions changes, also run make validate and make repo-hygiene so contract and
hygiene gates stay green.