ci: lift OSSF Scorecard score (3.7 → ~6.5+)#18
Conversation
- Add SECURITY.md (Security-Policy 0→10) - Add .github/dependabot.yml for gomod, npm, actions (Dep-Update 0→10) - Add explicit CodeQL workflow with push trigger (SAST 0→10) - SHA-pin all actions in ci.yml, release.yml, scorecard.yml (Pinned-Dependencies 4→10) - Per-job permissions scoping (Token-Permissions 0→10) - Branch protection applied to main via API (Branch-Protection 3→10, configured out-of-band) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 32 minutes and 50 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (6)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Summary
Bundles all the scorecard wins that don't require time or external review history:
Branch protection on `main` applied via API (out-of-band): linear history required, force-push/delete blocked, required status checks on 4 CI jobs, dismiss stale reviews → Branch-Protection 3→10.
Projected score
3.7 → ~6.5 from this PR alone. Remaining gaps (Maintained, Code-Review, Contributors, Fuzzing, CII-Best-Practices) are time- or process-bound and can't be fixed in a single PR.
Test plan