OpenSSF Scorecard fails on every PR and on main. The cause is entirely outside this repository, so it needs an owner decision rather than a code fix.
What happens
The job dies before any Scorecard rule is evaluated — it cannot pull the action image:
/usr/bin/docker pull gcr.io/openssf/scorecard-action:v2.4.0
Error response from daemon: Head "https://gcr.io/v2/openssf/scorecard-action/manifests/v2.4.0":
denied: This API method requires billing to be enabled. Please enable billing on project #367732848534
##[error]Docker pull failed with exit code 1
Billing is disabled on upstream OpenSSF's own GCR project. The job retries three times with backoff and gets the identical response each time.
Scope
Not PR-specific. OpenSSF Scorecard is red on main HEAD 9c8e3cf across 2026-09-05, 2026-09-07 and 2026-09-14, and on every PR since. It is currently advisory rather than required — PRs report mergeable_state=unstable rather than blocked — so it is noise rather than a merge blocker, but it is noise on every run and it trains reviewers to ignore a security check.
Options
- Move the workflow off
gcr.io. Newer ossf/scorecard-action releases are served from GHCR; pinning to one of those avoids the unbillable registry entirely. Most likely the real fix.
- Pin an older digest that is still served, as a stopgap.
- Disable the workflow until upstream restores billing, so the red check stops being background noise. Least preferred — it removes a security signal rather than repairing it.
I did not attempt any of these: .github/workflows/ is an owner-managed surface under AUTH-CI-OWNER, and widening a feature or remediation PR into it is the exact anti-pattern #265 is about. Say which option you want and I will prepare it as its own PR.
Observed on #264 (9c69038) and on main.
Generated by Claude Code
OpenSSF Scorecardfails on every PR and onmain. The cause is entirely outside this repository, so it needs an owner decision rather than a code fix.What happens
The job dies before any Scorecard rule is evaluated — it cannot pull the action image:
Billing is disabled on upstream OpenSSF's own GCR project. The job retries three times with backoff and gets the identical response each time.
Scope
Not PR-specific.
OpenSSF Scorecardis red onmainHEAD9c8e3cfacross 2026-09-05, 2026-09-07 and 2026-09-14, and on every PR since. It is currently advisory rather than required — PRs reportmergeable_state=unstablerather thanblocked— so it is noise rather than a merge blocker, but it is noise on every run and it trains reviewers to ignore a security check.Options
gcr.io. Newerossf/scorecard-actionreleases are served from GHCR; pinning to one of those avoids the unbillable registry entirely. Most likely the real fix.I did not attempt any of these:
.github/workflows/is an owner-managed surface underAUTH-CI-OWNER, and widening a feature or remediation PR into it is the exact anti-pattern #265 is about. Say which option you want and I will prepare it as its own PR.Observed on #264 (
9c69038) and onmain.Generated by Claude Code