Commit graph

4 commits

Author SHA1 Message Date
Mick Grove
3e0569d741 improve OpenSSF scorecard: tighten token permissions and add build provenance
Move write permissions from workflow top-level to job-level in cflite_batch,
cflite_pr, and release-docker workflows. Add sigstore build provenance
attestation to the release workflow via actions/attest-build-provenance.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-26 19:36:18 -07:00
Mick Grove
d609900d56 updated dependencies 2026-03-24 08:55:34 -07:00
Mick Grove
bd2d53b7b4 openssf scorecard suggested improvements 2026-03-20 07:45:37 -07:00
Mick Grove
5fa4ce59b7 openssf scorecard suggested improvements
Made-with: Cursor
2026-03-19 23:39:36 -07:00