Commit e754d2b
fix(ci): repair unparseable scorecard.yml that startup-kills the run (#187)
## The defect
`.github/workflows/scorecard.yml` was not valid YAML:
```yaml
permissions: read-all
actions: read
```
A scalar value with a mapping key indented beneath it:
```
yaml: line 12, column 10: mapping values are not allowed in this context
```
The file also carried a **second, well-formed `permissions:` block**
immediately below
the broken pair, so those two lines are pure debris from a permissions
sweep. Deleting
them leaves the intended permissions exactly as they were.
## Why this is worse than a red build
The run is still created, but it emits `jobs.total_count == 0` and
**never produces a
check run**. A *required* context therefore **never reports** — so an
unrepaired repo
looks **greener** than a repaired one. Screening on conclusion colour
hides this class
entirely; the only sound screen is the job count.
## Verification
- `yq` parses the file
- `jobs` is a non-empty map
- `jobs.analysis` is a pure reusable-workflow caller — `uses` present,
no `steps`, no `runs-on`
- `actionlint` clean
- the pin `8f2ee508` resolves (standards, 2026-09-08) and is **left
untouched** — this is a YAML-only fix
- commit is signed, `%G?` = `G`
## Context
Ten sibling repos already carry this same repair on open PRs. `bofig`
was the one member
of the family with **no** open repair PR, which is why it is still
broken on `main`.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_0178nN4Nm3neFRy5K9StZKnB
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>1 parent 6678798 commit e754d2b
1 file changed
Lines changed: 0 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
13 | | - | |
14 | 12 | | |
15 | 13 | | |
16 | 14 | | |
| |||
0 commit comments