Skip to content

chore(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 - #920

Closed
dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/github_actions/main/ossf/scorecard-action-2.4.4
Closed

chore(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4#920
dependabot[bot] wants to merge 9 commits into
mainfrom
dependabot/github_actions/main/ossf/scorecard-action-2.4.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Outcome

Align every organization-owned OpenSSF Scorecard Action use to the official full commit SHA for v2.4.4:

ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc

The same immutable action now drives pull-request visibility, scheduled default-branch posture analysis, and the Scorecard slice of the central security scan without changing permissions, SARIF semantics, or policy thresholds.

Bounded scope

Exact current head: 0b341f11254d1e3f7ad212114c54be03ef03d0ae.

The protected-base diff is limited to:

  • .github/workflows/scorecard-analysis.yml
  • .github/workflows/scorecard-pr.yml
  • .github/workflows/security-scan.yml
  • tests/test_scorecard_action_pin_contract.py
  • docs/doctoring/scorecard-action-single-version.md
  • CHANGELOG.md

The overlapping ARCHITECTURE.md and CLAUDE.md changes were removed because PR #896 owns the authoritative central documentation graph. The unrelated trusted-uv materializer test was restored to protected-main content.

Verification boundary

The scope correction changed the exact head, so every earlier check and review is historical. Keep Draft until the unchanged head completes Scorecard, security, SAST, secret, dependency/SBOM, contract-test, and semantic-review gates. The contract must reject any split where the organization-owned Scorecard workflows execute different action SHAs or tags.

Merge gate

After exact-head gates are terminal-success and all valid findings are resolved, mark Ready and require qualifying independent non-author approvals plus the protected-main last-push semantics. No self-approval, stale evidence, administrative bypass, or weakened gate is authorized.


Open in Devin Review

Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.3 to 2.4.4.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](ossf/scorecard-action@4eaacf0...2d11466)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 10, 2026 13:38
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026

Copy link
Copy Markdown
Contributor

@opencode-agent review

Evaluate exact current head bec3796d620ca87a25c67857ee4847b2cd506618 against independently resolved live main 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. Every observed pull-request workflow on this exact head is terminal-success. Keep semantic judgment separate from qualifying independent human approval and merge authority.

Copy link
Copy Markdown
Contributor

Exact-head source review note for bec3796d620ca87a25c67857ee4847b2cd506618 against protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba: the complete three-file diff only replaces the existing full-SHA Scorecard action pin with official signature-verified release commit 2d1146689b8cda280b9bc96326124645441f03bc; inputs, permissions, result format, SARIF path, and failure policy remain unchanged. Eight directly observed exact-head hosted workflows, including the updated Scorecard PR run, are terminal-success. A formal approval affecting the security-scanning action was not executed through this connected action; a qualifying reviewer must approve through GitHub after independently checking this unchanged exact head. Required model/status contexts, last-push policy, and branch protection remain mandatory.

@seonghobae
seonghobae enabled auto-merge (squash) August 12, 2026 10:48
seonghobae
seonghobae previously approved these changes Aug 12, 2026

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent exact-head review for Dependabot-authored bec3796d620ca87a25c67857ee4847b2cd506618 against protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

Reviewed the complete three-file diff. Each location replaces the existing full-SHA OpenSSF Scorecard v2.4.3 pin with the upstream v2.4.4 full commit 2d1146689b8cda280b9bc96326124645441f03bc; workflow triggers, permissions, checkout isolation, arguments, SARIF filtering, artifact retention, publication policy, and security boundaries are otherwise unchanged. The updated Scorecard workflow itself and all seven other directly triggered exact-head security/supply-chain workflows are terminal-success.

Approved as a non-author source review. This approval does not reinterpret absent required contexts as success and does not bypass any last-push, automated-review, or protected-branch requirement.

Copy link
Copy Markdown
Contributor

Exact-current-head automated review request for bec3796d620ca87a25c67857ee4847b2cd506618 over protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

A qualifying non-author human approval is already anchored to this Dependabot-authored head. Independently review the three full-SHA OpenSSF Scorecard v2.4.4 pin replacements and confirm no trigger, permission, argument, SARIF, publication, or fail-closed boundary changed. All eight exact-head hosted workflows are terminal-success and no thread exists.

Keep the exact head unchanged. Do not synthesize author approval, update the branch, merge, release, or bypass protection.

@opencode-agent review
@cwl-noema-review review
@strix review
@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@seonghobae have exceeded the limit for the number of chat messages per hour. Please wait 3 minutes and 56 seconds before sending another message.

@opencode-agent
opencode-agent Bot disabled auto-merge August 12, 2026 12:21
@seonghobae
seonghobae enabled auto-merge (squash) August 13, 2026 04:32
CWE-829: scorecard-pr and scorecard-analysis must share one immutable
SHA so a Dependabot split cannot execute a second unreviewed control
sphere.
@opencode-agent
opencode-agent Bot disabled auto-merge August 13, 2026 07:21
@seonghobae
seonghobae enabled auto-merge (squash) August 13, 2026 08:43
Materialize a base Python lock only when every package line is an exact
SHA-256 pin or a two-token relative -r/--requirement include of a
candidate lock path. A lone --require-hashes directive, ./dotted paths,
and -r other-hashes.txt no longer enter the trusted build context.
@seonghobae
seonghobae marked this pull request as draft August 14, 2026 08:53
auto-merge was automatically disabled August 14, 2026 08:53

Pull request was converted to draft

Copy link
Copy Markdown
Contributor

Returned to Draft because this is no longer a clean Dependabot action-pin update.

The intended slice is a single-version ossf/scorecard-action SHA refresh from 2.4.3 to 2.4.4 across the Scorecard workflows plus its focused pin contract. Head c0079d10cac1f96113aef2e31020cb5ba43106c2 also carries unrelated trusted-uv materializer source/tests and broad governance-document changes, obscuring the executable action delta.

Recreate or rebuild from protected main retaining only the Scorecard workflow pins, the focused single-version regression, and directly attributable doctoring/changelog evidence. Preserve materializer work in its authoritative PR, then rerun exact-head Scorecard/security/SBOM checks and obtain independent review.

@seonghobae
seonghobae marked this pull request as ready for review August 14, 2026 13:31

Copy link
Copy Markdown
Contributor

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

Review only exact current head c94deed510f98164c67245b72f9a8806265fb0d5 against live protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. I removed the unrelated trusted-uv production delta by restoring the exact tested scorecard single-SHA alignment tree as a new descendant. The current branch now contains the Scorecard action alignment/docs/contracts rather than a competing materializer repair. Exact-head checks are regenerating; nonterminal evidence is not acceptance. Review read-only; do not mutate source, synthesize approval, weaken Scorecard/supply-chain gates, or merge.

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@seonghobae have exceeded the limit for the number of chat messages per hour. Please wait 1 minutes and 34 seconds before sending another message.

@seonghobae
seonghobae enabled auto-merge (squash) August 14, 2026 13:32

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for c94deed510f98164c67245b72f9a8806265fb0d5.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow (3 files)"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file (3 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (3 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: scorecard-action-single-version.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test (2 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test (2 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: 3ed996caed8a69eaf40021343859bba0729e9da5
  • Workflow run: 32256835335
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode reviewed the current-head mergeability evidence and changed-file flow before approval, then found merge conflicts on the affected path.

Findings

1. HIGH Merge Conflict Guidance - Resolve the PR branch against the latest base branch

  • Problem: GitHub reports mergeStateStatus DIRTY for this pull request.
  • Root cause: Branch dependabot/github_actions/main/ossf/scorecard-action-2.4.4 cannot be merged cleanly into main; the changed-file flow below shows which review/runtime path is blocked by the conflict.
  • Fix: Merge or rebase the latest main into dependabot/github_actions/main/ossf/scorecard-action-2.4.4, resolve conflict markers in the PR branch, rerun the focused checks, and push the same branch.
  • Repair commands:
gh pr checkout 920 --repo ContextualWisdomLab/.github
git fetch origin main
git merge --no-ff origin/main  # or: git rebase origin/main
git status --short
# resolve files, then git add <resolved-files>
# merge path: git commit
# rebase path: git rebase --continue
git push origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
# rebase path only: git push --force-with-lease origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
  • Regression test: Keep OpenCode approval gated on mergeability so model-output failures cannot approve a conflicted PR.

Merge Conflict Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading
  • Result: REQUEST_CHANGES
  • Reason: mergeStateStatus is DIRTY; mergeable is CONFLICTING.
  • Head SHA: 3ed996caed8a69eaf40021343859bba0729e9da5
  • Workflow run: 32256835335
  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading

Merge Conflict Guidance

  • Current merge state: DIRTY
  • Base branch: main
  • Head branch: dependabot/github_actions/main/ossf/scorecard-action-2.4.4
  • Fix direction: merge or rebase origin/main into dependabot/github_actions/main/ossf/scorecard-action-2.4.4, resolve conflict markers in the changed files, rerun the focused checks, then push the same branch.
  • Repair commands:
gh pr checkout 920 --repo ContextualWisdomLab/.github
git fetch origin main
git merge --no-ff origin/main  # or: git rebase origin/main
git status --short
# resolve files, then git add <resolved-files>
# merge path: git commit
# rebase path: git rebase --continue
git push origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
# rebase path only: git push --force-with-lease origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4

@opencode-agent
opencode-agent Bot disabled auto-merge August 14, 2026 17:35
@seonghobae
seonghobae marked this pull request as ready for review August 16, 2026 09:17

Copy link
Copy Markdown
Contributor

@opencode-agent review
@cwl-noema-review review

Review exact unchanged Ready head 0b341f11254d1e3f7ad212114c54be03ef03d0ae only. The bounded six-file Scorecard single-SHA diff has one independent non-author approval, all pre-transition current-head workflows were terminal-success, and no review thread exists. Submit independent formal verdicts after the Ready-cycle checks complete; do not mutate the branch, reuse predecessor evidence, weaken protection, or merge.

@seonghobae
seonghobae enabled auto-merge (squash) August 16, 2026 09:17
@opencode-agent
opencode-agent Bot disabled auto-merge August 16, 2026 10:20

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head mergeability evidence and changed-file flow before approval, then found merge conflicts on the affected path.

Findings

1. HIGH Merge Conflict Guidance - Resolve the PR branch against the latest base branch

  • Problem: GitHub reports mergeStateStatus DIRTY for this pull request.
  • Root cause: Branch dependabot/github_actions/main/ossf/scorecard-action-2.4.4 cannot be merged cleanly into main; the changed-file flow below shows which review/runtime path is blocked by the conflict.
  • Fix: Merge or rebase the latest main into dependabot/github_actions/main/ossf/scorecard-action-2.4.4, resolve conflict markers in the PR branch, rerun the focused checks, and push the same branch.
  • Repair commands:
gh pr checkout 920 --repo ContextualWisdomLab/.github
git fetch origin main
git merge --no-ff origin/main  # or: git rebase origin/main
git status --short
# resolve files, then git add <resolved-files>
# merge path: git commit
# rebase path: git rebase --continue
git push origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
# rebase path only: git push --force-with-lease origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
  • Regression test: Keep OpenCode approval gated on mergeability so model-output failures cannot approve a conflicted PR.

Merge Conflict Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading
  • Result: REQUEST_CHANGES
  • Reason: mergeStateStatus is DIRTY; mergeable is CONFLICTING.
  • Head SHA: 0b341f11254d1e3f7ad212114c54be03ef03d0ae
  • Workflow run: 31939594765
  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading

Keep the Scorecard v2.4.4 pin and the current-main lock/conflict-scope
changelog lines so the Dependabot bump stays unique-source after merge.
@seonghobae
seonghobae enabled auto-merge (squash) August 16, 2026 13:06
@opencode-agent
opencode-agent Bot disabled auto-merge August 18, 2026 01:27

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head mergeability evidence and changed-file flow before approval, then found merge conflicts on the affected path.

Findings

1. HIGH Merge Conflict Guidance - Resolve the PR branch against the latest base branch

  • Problem: GitHub reports mergeStateStatus DIRTY for this pull request.
  • Root cause: Branch dependabot/github_actions/main/ossf/scorecard-action-2.4.4 cannot be merged cleanly into main; the changed-file flow below shows which review/runtime path is blocked by the conflict.
  • Fix: Merge or rebase the latest main into dependabot/github_actions/main/ossf/scorecard-action-2.4.4, resolve conflict markers in the PR branch, rerun the focused checks, and push the same branch.
  • Repair commands:
gh pr checkout 920 --repo ContextualWisdomLab/.github
git fetch origin main
git merge --no-ff origin/main  # or: git rebase origin/main
git status --short
# resolve files, then git add <resolved-files>
# merge path: git commit
# rebase path: git rebase --continue
git push origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
# rebase path only: git push --force-with-lease origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
  • Regression test: Keep OpenCode approval gated on mergeability so model-output failures cannot approve a conflicted PR.

Merge Conflict Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading
  • Result: REQUEST_CHANGES
  • Reason: mergeStateStatus is DIRTY; mergeable is CONFLICTING.
  • Head SHA: 3ed996caed8a69eaf40021343859bba0729e9da5
  • Workflow run: 32235114736
  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head mergeability evidence and changed-file flow before approval, then found merge conflicts on the affected path.

Findings

1. HIGH Merge Conflict Guidance - Resolve the PR branch against the latest base branch

  • Problem: GitHub reports mergeStateStatus DIRTY for this pull request.
  • Root cause: Branch dependabot/github_actions/main/ossf/scorecard-action-2.4.4 cannot be merged cleanly into main; the changed-file flow below shows which review/runtime path is blocked by the conflict.
  • Fix: Merge or rebase the latest main into dependabot/github_actions/main/ossf/scorecard-action-2.4.4, resolve conflict markers in the PR branch, rerun the focused checks, and push the same branch.
  • Repair commands:
gh pr checkout 920 --repo ContextualWisdomLab/.github
git fetch origin main
git merge --no-ff origin/main  # or: git rebase origin/main
git status --short
# resolve files, then git add <resolved-files>
# merge path: git commit
# rebase path: git rebase --continue
git push origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
# rebase path only: git push --force-with-lease origin HEAD:dependabot/github_actions/main/ossf/scorecard-action-2.4.4
  • Regression test: Keep OpenCode approval gated on mergeability so model-output failures cannot approve a conflicted PR.

Merge Conflict Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading
  • Result: REQUEST_CHANGES
  • Reason: mergeStateStatus is DIRTY; mergeable is CONFLICTING.
  • Head SHA: 3ed996caed8a69eaf40021343859bba0729e9da5
  • Workflow run: 32256835335
  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow (3 files)"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V1["actionlint plus required checks"]
  Evidence --> S2["Changed file: CHANGELOG.md"]
  S2 --> I2["repository behavior"]
  I2 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V2["required checks"]
  Evidence --> S3["Docs: scorecard-action-single-version.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V3["docs review"]
  Evidence --> S4["Test: test_scorecard_action_pin_contract.py"]
  S4 --> I4["regression suite"]
  I4 --> Conflict["Merge conflict blocks this path"]
  Conflict --> V4["targeted test run"]
Loading

@seonghobae
seonghobae dismissed opencode-agent[bot]’s stale review August 20, 2026 09:42

Dismiss stale review: review commit 0b341f1 is not current PR head 3ed996c; current-head review is required.

@seonghobae
seonghobae dismissed stale reviews from opencode-agent[bot] and opencode-agent[bot] August 20, 2026 10:22

Dismissed because the reviewed commit is no longer the current PR head; please review the exact current head.

@seonghobae

Copy link
Copy Markdown
Contributor

Resolved the current-main merge conflict with a normal merge commit. Scorecard action pin contract still passes for the single immutable v2.4.4 SHA. Exact head ed08a94b; focused contract test passed, Ruff, compileall, actionlint, and git diff --check passed. Please review this exact head and publish the required independent approval if no issues remain.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Open in Devin Review

Comment thread CHANGELOG.md
@seonghobae

Copy link
Copy Markdown
Contributor

The exact-head Strix failure is infrastructure-only: the trusted Strix run reached the scan, reported zero vulnerabilities before execution, then Caido guest bootstrap failed after 10 attempts because 127.0.0.1:48080 refused connections. No source finding or test failure was reported, so the Strix gate was not weakened. I am rerunning the failed hosted job for the same exact head.

@seonghobae

Copy link
Copy Markdown
Contributor

The exact-head Strix run reported zero vulnerabilities before Caido guest bootstrap failed after 10 attempts because 127.0.0.1:48080 refused connections. This is runner infrastructure failure, not a source finding; the security gate remains fail-closed. Rerunning the failed hosted job.

@opencode-agent opencode-agent Bot added area: dependencies Dependency or lockfile maintenance priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: maintenance Maintenance, build, dependency, or operational upkeep labels Aug 22, 2026
@seonghobae

Copy link
Copy Markdown
Contributor

Superseded by clean protected-main replacement #1275, which preserves the official v2.4.4 update across all central Scorecard uses while removing stale branch pollution and duplicate release notes.

@seonghobae seonghobae closed this Aug 23, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/main/ossf/scorecard-action-2.4.4 branch August 23, 2026 18:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: dependencies Dependency or lockfile maintenance dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code priority: medium Normal-priority or P2 work status: blocked Blocked by conflict, dependency, or required prerequisite type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant