Skip to content

Conversation

@cuioss-oliver
Copy link
Collaborator

Summary

  • Added workflow-level and job-level permissions to scorecards.yml matching the reusable workflow requirements
  • Replaced verbose credentials section in README.adoc with note that all secrets are managed at org level

Test plan

  • Verify build / build (21), build / build (25), build / sonar-build checks pass
  • After merge, trigger scorecards manually: gh workflow run scorecards.yml --ref main
  • Verify scorecards workflow succeeds with the new permissions

🤖 Generated with Claude Code

- Add workflow-level and job-level permissions to scorecards.yml
  matching the reusable workflow requirements (security-events,
  id-token, contents, actions, issues, pull-requests, checks)
- Replace verbose credentials section in README.adoc with note
  that all secrets are managed at org level

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@cuioss-oliver cuioss-oliver merged commit 9170478 into main Feb 3, 2026
7 checks passed
@cuioss-oliver cuioss-oliver deleted the feature/incorporate_cuioss_org branch February 3, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants