• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

prisma-risk / tsoracle / 26481193910
95%

Build:
DEFAULT BRANCH: main
Ran 26 May 2026 11:36PM UTC
Jobs 1
Files 89
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

26 May 2026 11:30PM UTC coverage: 94.938%. Remained the same
26481193910

push

github

web-flow
docs(security): document the SLSA-generator tag-ref exception (#540)

OpenSSF Scorecard's Pinned-Dependencies check flags our tag-ref on
slsa-framework/slsa-github-generator (`@v2.1.0`) — but the generator's
generate-builder.sh explicitly rejects SHA pins and exits 2 with
"Invalid ref: <sha>. Expected ref of the form refs/tags/vX.Y.Z". Two
upstream projects with overlapping mandates are at impasse here, and
the community consensus (including scorecard's own goreleaser.yaml) is
to accept the ~1-point Pinned-Dependencies deduction.

Add a "Supply chain integrity" section to SECURITY.md that:
- Describes the SLSA v1.0 build provenance we ship (link to the
  existing docs/release-signatures.md verification recipe).
- Documents the SLSA generator exception with upstream issue links
  (slsa-github-generator#722, slsa-verifier#12, scorecard#2174,
  scorecard#1406) so the deduction is auditable.
- Notes that scorecard's own project does the same thing, with a link
  to their goreleaser.yaml as canonical precedent.

Tighten the inline comment at the `uses:` line in release-sign.yml to
point at SECURITY.md for the full rationale rather than duplicating it.

13486 of 14205 relevant lines covered (94.94%)

387954.91 hits per line

Jobs
ID Job ID Ran Files Coverage
1 26481193910.1 26 May 2026 11:36PM UTC 89
94.94
GitHub Action Run
Source Files on build 26481193910
  • Tree
  • List 89
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #26481193910
  • cf5a8fd3 on github
  • Prev Build on main (#26480869009)
  • Next Build on main (#26481556687)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc