Skip to content

Test: Verify SCS/Scorecard works with fork PRs After PR Got Merged [DO NOT MERGE]#60

Closed
cosmir17 wants to merge 2 commits intomidnightntwrk:mainfrom
cosmir17:test/sean-fork-test-after-the-pr-got-merged
Closed

Test: Verify SCS/Scorecard works with fork PRs After PR Got Merged [DO NOT MERGE]#60
cosmir17 wants to merge 2 commits intomidnightntwrk:mainfrom
cosmir17:test/sean-fork-test-after-the-pr-got-merged

Conversation

@cosmir17
Copy link
Copy Markdown
Contributor

Purpose

Testing the SCS fix from PM-19431 to verify that Supply Chain Security scanning works correctly for fork PRs using GITHUB_TOKEN.

What this tests

Expected behavior

The CI should show:

  • ✅ Checkmarx scan runs via pull_request_target
  • ✅ "SCS/Scorecard: Enabled" in the logs
  • ✅ SCS parameters included in scan command
  • ✅ No permission errors for SCS token

Action required

  • Please DO NOT merge this PR
  • Will close once SCS functionality is verified
  • Check the Checkmarx scan logs for SCS results

Related to: PM-19431

@cosmir17 cosmir17 self-assigned this Sep 25, 2025
@cosmir17 cosmir17 requested a review from a team as a code owner September 25, 2025 21:20
@cosmir17
Copy link
Copy Markdown
Contributor Author

Production verification complete! ✅

The fork-friendly Checkmarx action is working perfectly:

  • Build succeeded with main branch
  • SCS/Scorecard enabled using github.token
  • Successfully scanning fork repository
  • No permission errors

Build log: https://github.com/midnightntwrk/midnight-node-docker/actions/runs/18021180983/job/51278610712?pr=60
PM-19431 is working. Fork PRs can now run security scans on public repos.
Closing this test PR as it has served its purpose.

Screenshot 2025-09-25 at 22 39 43

@cosmir17 cosmir17 closed this Sep 25, 2025
@cosmir17 cosmir17 deleted the test/sean-fork-test-after-the-pr-got-merged branch September 25, 2025 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant