kingfisher/.github/workflows
Mick Grove 3e0569d741 improve OpenSSF scorecard: tighten token permissions and add build provenance
Move write permissions from workflow top-level to job-level in cflite_batch,
cflite_pr, and release-docker workflows. Add sigstore build provenance
attestation to the release workflow via actions/attest-build-provenance.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-26 19:36:18 -07:00
..
cflite_batch.yml improve OpenSSF scorecard: tighten token permissions and add build provenance 2026-03-26 19:36:18 -07:00
cflite_pr.yml improve OpenSSF scorecard: tighten token permissions and add build provenance 2026-03-26 19:36:18 -07:00
ci.yml updated dependencies 2026-03-24 08:55:34 -07:00
pypi.yml updated dependencies 2026-03-24 08:55:34 -07:00
release-docker.yml improve OpenSSF scorecard: tighten token permissions and add build provenance 2026-03-26 19:36:18 -07:00
release-provenance.yml openssf scorecard suggested improvements 2026-03-19 20:45:58 -07:00
release.yml improve OpenSSF scorecard: tighten token permissions and add build provenance 2026-03-26 19:36:18 -07:00