Skip to content

OpenSSF Scorecard fails repo-wide: upstream gcr.io/openssf image is unpullable (billing disabled) #269

Description

@cryptoxdog

OpenSSF Scorecard fails on every PR and on main. The cause is entirely outside this repository, so it needs an owner decision rather than a code fix.

What happens

The job dies before any Scorecard rule is evaluated — it cannot pull the action image:

/usr/bin/docker pull gcr.io/openssf/scorecard-action:v2.4.0
Error response from daemon: Head "https://gcr.io/v2/openssf/scorecard-action/manifests/v2.4.0":
denied: This API method requires billing to be enabled. Please enable billing on project #367732848534
##[error]Docker pull failed with exit code 1

Billing is disabled on upstream OpenSSF's own GCR project. The job retries three times with backoff and gets the identical response each time.

Scope

Not PR-specific. OpenSSF Scorecard is red on main HEAD 9c8e3cf across 2026-09-05, 2026-09-07 and 2026-09-14, and on every PR since. It is currently advisory rather than required — PRs report mergeable_state=unstable rather than blocked — so it is noise rather than a merge blocker, but it is noise on every run and it trains reviewers to ignore a security check.

Options

  1. Move the workflow off gcr.io. Newer ossf/scorecard-action releases are served from GHCR; pinning to one of those avoids the unbillable registry entirely. Most likely the real fix.
  2. Pin an older digest that is still served, as a stopgap.
  3. Disable the workflow until upstream restores billing, so the red check stops being background noise. Least preferred — it removes a security signal rather than repairing it.

I did not attempt any of these: .github/workflows/ is an owner-managed surface under AUTH-CI-OWNER, and widening a feature or remediation PR into it is the exact anti-pattern #265 is about. Say which option you want and I will prepare it as its own PR.

Observed on #264 (9c69038) and on main.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions