Documentation
¶
Overview ¶
Command scaffold-render writes every profile of the scaffolded release workflows (scaffold.AuditProfiles) into a directory, one <profile>/.github/workflows/ tree each, for CI's zizmor job to audit (iss-2609251939472371). The committed workflows are the abcd profile only, so without it the profiles a managed repository receives were held to the in-repo audit's two finding classes and never to zizmor's pinning, permission and credential audits.
Usage: go run ./cmd/scaffold-render <dir>. The directory is the caller's scratch space; nothing outside it is written. Exit 0 written, 1 a fault, 2 a usage error.
Click to show internal directories.
Click to hide internal directories.