Skip to content

Add org-level Octo STS policy for applied-ai scorecard#2

Open
marc-barry wants to merge 1 commit into
developfrom
add-octo-sts-ci-automation-policy
Open

Add org-level Octo STS policy for applied-ai scorecard#2
marc-barry wants to merge 1 commit into
developfrom
add-octo-sts-ci-automation-policy

Conversation

@marc-barry

Copy link
Copy Markdown

Org-level Octo STS trust policy: the weekly refresh-scorecard workflow in applied-ai reads every netboxlabs repo to compute AI-readiness scorecards, replacing the NBL CI Automation GitHub App's org-wide read.

  • repositories: is omitted on purpose — the token may read all installation repos, but claim_pattern pins minting to exactly one workflow on one branch of one repo, and the grant is read-only.
  • This repo is public, so the policy (a grant statement, no secrets) is world-readable — deliberate and acceptable.
  • Inert until the scorecard workflow is converted (phase 2).

🤖 Generated with Claude Code

Read-only, claim-pinned to applied-ai's refresh-scorecard workflow on
main; repositories: omitted so the weekly scorecard can read every
installation repo. Replaces the NBL CI Automation app's org-wide read.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant