Skip to content

ci: bump pinned ossf/scorecard-action to v2.4.4 (conformance drift) - #121

Merged
sweetrb merged 1 commit into
mainfrom
scorecard-244
Aug 5, 2026
Merged

ci: bump pinned ossf/scorecard-action to v2.4.4 (conformance drift)#121
sweetrb merged 1 commit into
mainfrom
scorecard-244

Conversation

@sweetrb

@sweetrb sweetrb commented Aug 5, 2026

Copy link
Copy Markdown
Owner

Restores the byte-identical workflow set across the four servers.

Dependabot's weekly github-actions group PR bumped ossf/scorecard-action to 2d1146689b8cda280b9bc96326124645441f03bc (v2.4.4) in apple-mail-mcp (#134) and apple-numbers-mcp (#56) today, but silently skipped this repo and its sibling — the known group-skip failure mode. ./conformance-check.sh was reporting:

DRIFT: .github/workflows/scorecard.yml differs: apple-notes-mcp vs apple-mail-mcp
DRIFT: .github/workflows/scorecard.yml differs: apple-photos-mcp vs apple-mail-mcp

The drift is exactly one line — the pinned SHA on line 29 — and nothing fails on its own when it happens, which is what makes it worth catching in the conformance sweep rather than waiting for the next group PR to maybe include the laggards.

No version bump: .github/ is not shipped bytes, so version-guard does not require one and the CHANGELOG entry stays under [Unreleased] with no heading of its own.

Dependabot's weekly github-actions group PR landed v2.4.4 in apple-mail-mcp
(#134) and apple-numbers-mcp (#56) today but silently skipped this repo, so
conformance-check.sh reports:

  DRIFT: .github/workflows/scorecard.yml differs

The four servers are meant to carry a byte-identical workflow set, and a
group-skip is the recurring way that invariant breaks -- it is invisible
unless conformance-check.sh is run, because nothing fails on its own.

.github/ is not shipped bytes, so version-guard owes no version bump here;
the CHANGELOG entry goes under [Unreleased] with no heading of its own.
@sweetrb
sweetrb merged commit b7d05e7 into main Aug 5, 2026
8 checks passed
@sweetrb
sweetrb deleted the scorecard-244 branch August 5, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant