🌱 Migrate cron/batch scanning pipeline to ossf/scorecard-infra - #5210
Open
justaugustus wants to merge 6 commits into
Open
justaugustus wants to merge 6 commits into
justaugustus wants to merge 6 commits into
Conversation
justaugustus
temporarily deployed
to
integration-test
September 1, 2026 22:54 — with
GitHub Actions
Inactive
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5210 +/- ##
==========================================
+ Coverage 66.80% 75.59% +8.78%
==========================================
Files 230 251 +21
Lines 16602 13958 -2644
==========================================
- Hits 11091 10551 -540
+ Misses 4808 3406 -1402
+ Partials 703 1 -702 🚀 New features to boost your workflow:
|
This was referenced Sep 8, 2026
|
This pull request has been marked stale because it has been open for 10 days with no activity |
Walentalien
reviewed
Sep 25, 2026
The batch scanning pipeline (PubSub controller, workers, CII worker, BigQuery transfer, release webhook, GitHub token-pool server, and the projects.csv/gitlab-projects.csv scan inventories) has been imported into ossf/scorecard-infra with full commit history. GCP cron stopped running 2026-08-31 when the openssf GCP project was turned down, so this deletion removes no working function. Leave a tombstone at cron/README.md rather than a bare 404: the scan inventories are a high-traffic community contribution surface linked from external docs and old bookmarks. Announced in ossf#5208. Assisted-by: LLM Signed-off-by: Stephen Augustus <foo@auggie.dev>
Remove the Makefile targets, CI jobs, Dependabot paths, and coverage ignore that existed solely to build and validate the now-deleted batch pipeline: six docker/ko image targets, the add-projects/ validate-projects jobs, the build-proto protobuf codegen path (owned by scorecard-infra's cron/data now), and the GitHub token-pool server's build rule. All of this already has a live equivalent in ossf/scorecard-infra's CI (docker_matrix in build-images.yml, add-projects/validate-projects in presubmits.yml, publish-cron-images.yml) -- nothing here drops coverage, it just stops duplicating it upstream. Assisted-by: LLM Signed-off-by: Stephen Augustus <foo@auggie.dev>
Point CONTRIBUTING.md, README.md, and the Pinned-Dependencies check's Dockerfile example at ossf/scorecard-infra, where cron/ (including the projects.csv/gitlab-projects.csv scan inventories) now lives. Also drop CONTRIBUTING.md's two already-dead TOC entries for a dailyscore-cronjob section that no longer has a matching heading, and update cloudbuild/README.md now that only the scorecard image builds here. docs/checks.md is regenerated via `make generate-docs` from the checks.yaml edit, not hand-edited. Assisted-by: LLM Signed-off-by: Stephen Augustus <foo@auggie.dev>
Add an issue-template contact link so someone opening an issue to ask for their repository to be added to the weekly scan lands on ossf/scorecard-infra's contribution path instead of filing here. Assisted-by: LLM Signed-off-by: Stephen Augustus <foo@auggie.dev>
##@ TODO(ossf#744) rendered literally as a `make help` section header. Now that this PR has trimmed the docker/ko image targets down to just ko-images and scorecard-ko, give the section its real name and add descriptions so both targets actually show up under it. Assisted-by: LLM Signed-off-by: Stephen Augustus <foo@auggie.dev>
Both scorecard.yaml and scorecard-tag.yaml built and pushed to gcr.io/openssf/scorecard -- the same openssf GCP project that stopped running the batch scanning pipeline on 2026-08-31. Nothing in .github/workflows references these Cloud Build configs; they were only ever driven by GCP-side triggers, which no longer exist. Assisted-by: LLM Signed-off-by: Stephen Augustus <foo@auggie.dev>
justaugustus
force-pushed
the
remove-cron-batch-pipeline
branch
from
September 28, 2026 05:28
a211d3f to
ddcbec5
Compare
ossf/scorecard-infra
justaugustus
marked this pull request as ready for review
September 28, 2026 17:52
justaugustus
requested review from
spencerschrock
and
a lite review from Copilot
and removed request for
a team
September 28, 2026 17:52
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Address the unresolved documentation, inventory-path, and Go module cleanup findings before approval.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Migrates the batch-scanning pipeline and token server to ossf/scorecard-infra, removing duplicated infrastructure from this repository.
Changes:
- Removes cron source, tests, fixtures, manifests, and build configurations.
- Removes obsolete CI, Dependabot, Codecov, and Cloud Build integration.
- Updates documentation and migration links.
- Follow-ups remain for stale documentation links, inventory redirects, and unused Go dependencies.
| File | Summary |
|---|---|
README.md |
Updates inventory link; public data instructions need follow-up. |
docs/checks/internal/checks.yaml |
Updates Dockerfile reference. |
docs/checks.md |
Updates Dockerfile reference. |
cron/worker/worker.go |
Removes migrated worker. |
cron/worker/worker_test.go |
Removes worker tests. |
cron/README.md |
Adds migration tombstone; direct inventory paths need preservation. |
cron/monitoring/printer.go |
Removes monitoring code. |
cron/monitoring/exporter.go |
Removes monitoring exporter. |
cron/k8s/worker.yaml |
Removes worker deployment. |
cron/k8s/worker.release.yaml |
Removes release worker deployment. |
cron/k8s/webhook.release.yaml |
Removes webhook deployment. |
cron/k8s/transfer.yaml |
Removes transfer job. |
cron/k8s/transfer.release.yaml |
Removes release transfer job. |
cron/k8s/transfer.release-raw.yaml |
Removes raw release transfer job. |
cron/k8s/transfer-raw.yaml |
Removes raw transfer job. |
cron/k8s/README.md |
Removes obsolete deployment documentation. |
cron/k8s/controller.yaml |
Removes controller deployment. |
cron/k8s/controller.release.yaml |
Removes release controller deployment. |
cron/k8s/cii.yaml |
Removes CII job. |
cron/k8s/auth.yaml |
Removes authentication deployment. |
cron/internal/worker/Dockerfile |
Removes worker image definition. |
cron/internal/webhook/main.go |
Removes migrated webhook. |
cron/internal/webhook/Dockerfile |
Removes webhook image definition. |
cron/internal/shuffle/main.go |
Removes migrated shuffler. |
cron/internal/pubsub/subscriber.go |
Removes Pub/Sub subscriber. |
cron/internal/pubsub/subscriber_gocloud.go |
Removes GoCloud subscriber. |
cron/internal/pubsub/subscriber_gocloud_test.go |
Removes subscriber tests. |
cron/internal/pubsub/subscriber_gcs.go |
Removes GCS subscriber. |
cron/internal/pubsub/publisher.go |
Removes Pub/Sub publisher. |
cron/internal/pubsub/publisher_test.go |
Removes publisher tests. |
cron/internal/format/testdata/valid.schema |
Removes schema fixture. |
cron/internal/format/testdata/check6.json |
Removes result fixture. |
cron/internal/format/testdata/check5.json |
Removes result fixture. |
cron/internal/format/testdata/check4.json |
Removes result fixture. |
cron/internal/format/testdata/check3.json |
Removes result fixture. |
cron/internal/format/testdata/check2.json |
Removes result fixture. |
cron/internal/format/testdata/check1.json |
Removes result fixture. |
cron/internal/format/testdata/bq-valid.schema |
Removes schema fixture. |
cron/internal/format/schema_gen.go |
Removes schema generator. |
cron/internal/format/schema_gen_test.go |
Removes schema tests. |
cron/internal/format/mock_doc.go |
Removes format test mock. |
cron/internal/format/json.v2.schema |
Removes JSON schema. |
cron/internal/format/json.raw.schema |
Removes raw JSON schema. |
cron/internal/format/json.go |
Removes JSON formatter. |
cron/internal/format/json_raw_results.go |
Removes raw result formatter. |
cron/internal/format/json_raw_results_test.go |
Removes formatter tests. |
cron/internal/format/bq.raw.schema |
Removes BigQuery schema. |
cron/internal/emulator/README.md |
Removes emulator documentation. |
cron/internal/emulator/projects.csv |
Removes emulator inventory. |
cron/internal/emulator/fakegcs/ossf-scorecard-rawdata/.gitignore |
Removes emulator fixture. |
cron/internal/emulator/fakegcs/ossf-scorecard-data2/.gitignore |
Removes emulator fixture. |
cron/internal/emulator/fakegcs/ossf-scorecard-cron-results/.gitignore |
Removes emulator fixture. |
cron/internal/emulator/fakegcs/ossf-scorecard-cii-data/.gitignore |
Removes emulator fixture. |
cron/internal/emulator/config.yaml |
Removes emulator configuration. |
cron/internal/data/validate/main.go |
Removes inventory validator. |
cron/internal/data/add/testdata/skip_latest.csv |
Removes test fixture. |
cron/internal/data/add/testdata/skip_empty.csv |
Removes test fixture. |
cron/internal/data/add/testdata/skip_empty_2.csv |
Removes test fixture. |
cron/internal/data/add/testdata/skip_duplicates.csv |
Removes test fixture. |
cron/internal/data/add/testdata/no_change.csv |
Removes test fixture. |
cron/internal/data/add/testdata/add_metadata.csv |
Removes test fixture. |
cron/internal/data/add/main.go |
Removes inventory tool. |
cron/internal/data/add/main_test.go |
Removes inventory tool tests. |
cron/internal/controller/testdata/getPrefix/marker |
Removes controller fixture. |
cron/internal/controller/main.go |
Removes batch controller. |
cron/internal/controller/Dockerfile |
Removes controller image definition. |
cron/internal/controller/bucket.go |
Removes bucket input logic. |
cron/internal/controller/bucket_test.go |
Removes controller tests. |
cron/internal/cii/main.go |
Removes CII worker. |
cron/internal/cii/Dockerfile |
Removes CII image definition. |
cron/internal/cdn/client.go |
Removes CDN client. |
cron/internal/cdn/client_test.go |
Removes CDN tests. |
cron/internal/bq/transfer.go |
Removes transfer logic. |
cron/internal/bq/main.go |
Removes transfer executable. |
cron/internal/bq/Dockerfile |
Removes transfer image definition. |
cron/data/writer.go |
Removes inventory writer. |
cron/data/writer_test.go |
Removes writer tests. |
cron/data/testdata/summary_test/invalid/unknown_file |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.26/020003/shard-1234567 |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.26/020003/shard-0000001 |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.26/020003/shard-0000000 |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.26/020003/.shard_metadata |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.19/020001/shard-0000001 |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.19/020001/shard-0000000 |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.19/020001/.transfer_complete |
Removes summary fixture. |
cron/data/testdata/summary_test/basic/2022.09.19/020001/.shard_metadata |
Removes summary fixture. |
cron/data/testdata/split_file.csv |
Removes iterator fixture. |
cron/data/testdata/split_file_empty.csv |
Removes iterator fixture. |
cron/data/testdata/only_header.csv |
Removes iterator fixture. |
cron/data/testdata/no_header.csv |
Removes iterator fixture. |
cron/data/testdata/ignore_header.csv |
Removes iterator fixture. |
cron/data/testdata/failing_urls.csv |
Removes iterator fixture. |
cron/data/testdata/extra_column.csv |
Removes iterator fixture. |
cron/data/testdata/empty_row.csv |
Removes iterator fixture. |
cron/data/testdata/comment.csv |
Removes iterator fixture. |
cron/data/testdata/blob_test/subdir/nested/key5.txt |
Removes blob fixture. |
cron/data/testdata/blob_test/subdir/key4.txt |
Removes blob fixture. |
cron/data/testdata/blob_test/key3.txt |
Removes blob fixture. |
cron/data/testdata/blob_test/key2.txt |
Removes blob fixture. |
cron/data/testdata/blob_test/key1.txt |
Removes blob fixture. |
cron/data/testdata/basic.csv |
Removes iterator fixture. |
cron/data/testdata/basic-with-gitlab.csv |
Removes iterator fixture. |
cron/data/testdata/basic-gitlab-only.csv |
Removes iterator fixture. |
cron/data/summary.go |
Removes bucket summary logic. |
cron/data/summary_test.go |
Removes summary tests. |
cron/data/request.proto |
Removes batch request protobuf. |
cron/data/README.md |
Removes protobuf documentation. |
cron/data/metadata.proto |
Removes metadata protobuf. |
cron/data/metadata.pb.go |
Removes generated protobuf code. |
cron/data/iterator.go |
Removes inventory iterator. |
cron/data/iterator_test.go |
Removes iterator tests. |
cron/data/format.go |
Removes CSV formatting types; dependency cleanup remains needed. |
cron/data/format_test.go |
Removes formatting tests. |
cron/data/blob.go |
Removes blob utilities. |
cron/data/blob_test.go |
Removes blob tests. |
cron/config/testdata/optional_maps.yaml |
Removes configuration fixture. |
cron/config/testdata/missing_field.yaml |
Removes configuration fixture. |
cron/config/testdata/basic.yaml |
Removes configuration fixture. |
cron/config/config.yaml |
Removes cron configuration. |
cron/cloudbuild/worker.yaml |
Removes migrated build config. |
cron/cloudbuild/webhook.release.yaml |
Removes migrated build config. |
cron/cloudbuild/transfer.yaml |
Removes migrated build config. |
cron/cloudbuild/controller.yaml |
Removes migrated build config. |
cron/cloudbuild/cii.yaml |
Removes migrated build config. |
CONTRIBUTING.md |
Redirects scan contributions; TOC anchor needs updating. |
cloudbuild/scorecard.yaml |
Removes obsolete Cloud Build config. |
cloudbuild/scorecard-tag.yaml |
Removes obsolete tagged build config. |
cloudbuild/README.md |
Removes obsolete Cloud Build documentation. |
clients/githubrepo/roundtripper/tokens/server/main.go |
Removes migrated token server. |
clients/githubrepo/roundtripper/tokens/server/Dockerfile |
Removes token server image definition. |
clients/githubrepo/roundtripper/tokens/server/cloudbuild.yaml |
Removes token server build config. |
.gitignore |
Removes obsolete cron entries. |
.github/workflows/main.yml |
Removes cron and protobuf CI jobs. |
.github/workflows/docker.yml |
Removes cron image jobs. |
.github/ISSUE_TEMPLATE/config.yml |
Adds infrastructure contact link. |
.github/dependabot.yml |
Removes obsolete paths. |
.codecov.yml |
Removes cron coverage exclusion. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+7
to
+9
| scheduled removal date: `cron/internal/data/projects.csv` and `gitlab-projects.csv` | ||
| are high-traffic community contribution surfaces linked from external docs and old | ||
| bookmarks, and a 404 there costs more than one retained file. |
Comment on lines
+170
to
+173
| The list of projects that are checked is available in | ||
| [`cron/internal/data/projects.csv`](https://github.com/ossf/scorecard-infra/blob/main/cron/internal/data/projects.csv) | ||
| in [`ossf/scorecard-infra`](https://github.com/ossf/scorecard-infra), where the batch | ||
| scanning pipeline now lives. If you would like us to track more, please feel free to |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


What kind of change does this PR introduce?
Infra/Other: completes the repository split of the batch scanning pipeline
that
migrate-batch-pipeline(an OpenSpec change inossf/scorecard-infra)started.
cron/was already imported intoossf/scorecard-infrawith itsfull commit history; this PR removes the now-duplicated copy here.
What is the current behavior?
cron/(the PubSub controller, batch/CII workers, BigQuery transfer,release webhook, GitHub token-pool server, and the
projects.csv/gitlab-projects.csvscan inventories) lives in this repository, alongsideits Makefile targets, CI jobs, and Dependabot paths. The scan engine
(
checker,checks,probes,pkg/scorecard, etc.) does not import anyof it. GCP cron itself stopped running 2026-08-31 when the
openssfGCPproject was turned down.
What is the new behavior (if this is a feature change)?
cron/andclients/githubrepo/roundtripper/tokens/server/are removed.cron/README.mdbecomes a tombstone pointing toossf/scorecard-infra'scron/— retained indefinitely rather than on aremoval date, since the scan inventories are a high-traffic community
contribution surface linked from external docs and old bookmarks.
Makefile targets, CI jobs (
docker_matrix,build-matrix's cron entries,add-projects/validate-projects,build-proto), Dependabot paths, the.codecov.ymlignore, and.gitignoreentries that existed solely tobuild/validate the removed code are stripped. All of it already has a
live equivalent in
ossf/scorecard-infra's CI.cloudbuild/is also removed: both configs there built and pushed togcr.io/openssf/scorecard, the sameopenssfGCP project that stoppedrunning cron — nothing references them from GitHub Actions.
CONTRIBUTING.md,README.md, and the Pinned-Dependencies check'sDockerfile example now point at
ossf/scorecard-infra.A new issue-template contact link redirects "add my repo to the weekly
scan" requests there too.
The Makefile's
##@ TODO(#744)help section is renamed to##@ Imagesand its remaining targets (
ko-images,scorecard-ko) get help text,per review feedback.
Tests for the changes have been added (for bug fixes/features)
N/A — this is a deletion. Verified instead via a full build/test/lint
pass (see below).
Which issue(s) this PR fixes
Refs #5208
Special notes for your reviewer
a repository split, not a rewrite. No Scorecard check, probe, score, or
output format changes.
cron/dataandcron/configare the only public (non-internal)packages under the removed tree;
migrate-batch-pipeline's discoveryphase found zero external Go importers via pkg.go.dev and GitHub code
search, so this is a clean delete rather than one needing a deprecation
window.
clients/githubrepo/roundtripper/tokens/(the parent package —roundtripper.go/transport.go's dependency) is untouched; only itsserver/subdirectory (the standalone token-pool RPC server) moved.relies on for sign-off on the projects.csv contribution path moving. Flag
if the Steering Committee wants a dedicated notice for this specific
removal before it merges.
main(2026-09-28) and re-verified on this branch:go build ./...,go vet ./...,SKIP_GINKGO=1 go test ./..., andmake generate-docs(no-op) all pass.golangci-lint runshows the sametwo pre-existing findings (
policy/policy.go,policy/policy_test.go)present on plain
main— unrelated to this diff.actionlint/zizmoron the edited workflows show no new findings (fewer, since whole jobs
were deleted).
Does this PR introduce a user-facing change?