Skip to content

allstar: enable SARIF upload for scorecard policy#75

Merged
justaugustus merged 1 commit intomainfrom
allstar-sarif-upload
Mar 22, 2026
Merged

allstar: enable SARIF upload for scorecard policy#75
justaugustus merged 1 commit intomainfrom
allstar-sarif-upload

Conversation

@justaugustus
Copy link
Copy Markdown
Member

Summary

  • Enable SARIF upload in the Allstar Scorecard policy config

Context

Testing the evidence upload feature from ossf/allstar#796. This adds upload: {sarif: true} to the existing Scorecard policy config so that scan results are uploaded to each repo's Security > Code Scanning tab.

Test plan

  • Run self-hosted Allstar with -once flag against this org
  • Verify SARIF appears in repo Security tabs
  • Revert after testing is complete

🤖 Generated with Claude Code

Add upload.sarif: true to the Scorecard policy config. This enables
uploading Scorecard SARIF results to each repo's Security > Code
Scanning tab.

Requires ossf/allstar#796 (evidence-upload branch).

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Stephen Augustus <foo@auggie.dev>
@kusari-inspector
Copy link
Copy Markdown

⚠️ Workspace Mapping Required

Hello! We noticed that your GitHub organization is not yet mapped to a Kusari workspace. Kusari Inspector now requires installations to be associated with a Kusari workspace.

⚠️ NOTE: Only the admin who installed the Kusari GitHub App can complete these steps. If the admin is unable to complete these steps, please contact support@kusari.dev

To complete the setup:

  1. Visit https://console.us.kusari.cloud/auth/github and log in via github
  2. If you have only one workspace, it will be automatically selected for you
  3. Once the mapping is complete, return here and create a new comment with: @kusari-inspector re-run

This will trigger the analysis to run again.

For more information, or if you need help, visit https://github.com/kusaridev/community/discussions

@justaugustus justaugustus merged commit f483a37 into main Mar 22, 2026
1 check passed
@justaugustus justaugustus deleted the allstar-sarif-upload branch March 22, 2026 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant