Skip to content

docs(library): turn Helpful GitHub Actions into a Privateer scan guide - #56

Merged
eddie-knight merged 1 commit into
mainfrom
rev-442-privateer-actions-guide
Oct 6, 2026
Merged

eddie-knight merged 1 commit into
mainfrom
rev-442-privateer-actions-guide

Conversation

@jmeridth

@jmeridth jmeridth commented Oct 6, 2026

Copy link
Copy Markdown
Member

What/Why

The Mechanizer badge's Option 1 linked to a page that only pointed at the OSPS Baseline Action's README, which is out of date (older catalog, v1.5.1, classic tokens). This turns that section into a step-by-step guide: create a token, add a pinned workflow, run it, and read the results.

Proof it works

npm ci --ignore-scripts, npm run typecheck and npm run build pass. The action SHAs match this site's own working osps-baseline.yaml.

Risk

Low. Content only.

AI role

Drafted by Claude Opus 5.5 from this site's scan workflow, the mechanizer skill and the action README. Reviewed by Jason.

Review focus

The fine-grained token permissions (Actions, Administration, Code scanning alerts, Contents, all read) mirror this site's octo-sts policy but haven't been tried as a PAT. Also whether the copy-paste workflow keeps fail-on-error: "true".

Closes REV-442

## What/Why

Mechanizer Option 1 linked to a page that only pointed at the action's README, and that
README is stale (catalog 2026-02, v1.5.1, classic PATs). Participants without an AI agent
had no step-by-step path to scan their repo and read the results.

## Proof it works

`npm ci --ignore-scripts`, `npm run typecheck` and `npm run build` pass. The action,
checkout and upload-artifact SHAs were resolved from the GitHub API today and match
this site's own working osps-baseline.yaml.

## Risk

Low. Content only. Two Markdown files.

## AI role

Drafted by Claude Opus 5.5 from the site's working workflow, the mechanizer skill and the
action README; reviewed by Jason.

## Review focus

The fine-grained PAT permission list (Actions, Administration, Code scanning alerts,
Contents, all read) mirrors this site's octo-sts policy but hasn't been tried as a PAT.
Also the choice to keep `fail-on-error: "true"` (red job on failed controls) in the
copy-paste workflow.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth added the mark-ready-when-ready Mark this draft PR ready for review once checks pass label Oct 6, 2026
@jmeridth jmeridth self-assigned this Oct 6, 2026
@github-actions github-actions Bot added documentation Improvements or additions to documentation release labels Oct 6, 2026
@github-actions
github-actions Bot marked this pull request as ready for review October 6, 2026 13:30
@github-actions
github-actions Bot requested a review from a team as a code owner October 6, 2026 13:30
@github-actions github-actions Bot removed the mark-ready-when-ready Mark this draft PR ready for review once checks pass label Oct 6, 2026
@jmeridth
jmeridth requested a review from eddie-knight October 6, 2026 15:56
@eddie-knight
eddie-knight merged commit 188c96a into main Oct 6, 2026
4 of 5 checks passed
@eddie-knight
eddie-knight deleted the rev-442-privateer-actions-guide branch October 6, 2026 15:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants