Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

scorecard pipeline is failing in master branch #1566

Closed
ytsarev opened this issue May 19, 2024 · 5 comments · Fixed by #1567 or #1626
Closed

scorecard pipeline is failing in master branch #1566

ytsarev opened this issue May 19, 2024 · 5 comments · Fixed by #1567 or #1626

Comments

@ytsarev
Copy link
Member

ytsarev commented May 19, 2024

It's happening for a while, example https://github.com/k8gb-io/k8gb/actions/runs/9150847377

@ytsarev
Copy link
Member Author

ytsarev commented May 19, 2024

@jkremser as a supply chain master, do you see there some obvious fix? :)

@ytsarev ytsarev changed the title scorecard pipeline is failing in master scorecard pipeline is failing in master branch May 19, 2024
@jkremser
Copy link
Member

🤞 #1567

@ytsarev
Copy link
Member Author

ytsarev commented May 20, 2024

@jkremser, thanks a ton for the quick attempt! https://github.com/k8gb-io/k8gb/actions/runs/9157536246/job/25174078930 unfortunately, it still fails

@ytsarev ytsarev reopened this May 20, 2024
@ytsarev
Copy link
Member Author

ytsarev commented Jun 7, 2024

breadcrumb ossf/scorecard-action#997

@ytsarev
Copy link
Member Author

ytsarev commented Jun 30, 2024

2024/06/30 12:56:35 error signing scorecard json results: error signing payload: getting key from Fulcio: verifying SCT: updating local metadata and targets: error updating to TUF remote mirror: invalid key

which is matching the issue above

ytsarev added a commit to ytsarev/k8gb that referenced this issue Jun 30, 2024
* Fixes k8gb-io#1566
* Attemp is based on info from ossf/scorecard-action#997

Signed-off-by: Yury Tsarev <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants