Skip to content

Conversation

@trumant
Copy link
Contributor

@trumant trumant commented May 7, 2025

This PR resolves a failing test in #26 that is not getting run in the CI checks of that PR

make covcheck
Running tests and generating coverage output ...
{{2025-01-01 2024-12-31 2.0.0 https://github.com/ossf/security-insights-spec This file contains the security information for the Security Insights project. } 0x14000246300 0x14000246400}2025/05/07 12:05:22 error reading Security Insights data from ossf/si-tooling/.github/security-insights.yml: error unmarshalling parent SI: [7:1] unexpected key name
>  7 | <!DOCTYPE html>
   8 | <html
   9 |   lang="en"
  10 | 
  11 |   data-color-mode="auto" data-light-theme="light" data-dark-theme="dark"
  12 |   data-a11y-animated-images="system" data-a11y-link-underlines="true"
  13 | 
  14 |   >
  15 | 
  16 | 
  17 | 
  18 |   <head>
  19 |     <meta charset="utf-8">
  20 |   <link rel="dns-prefetch" href="https://github.githubassets.com">
  21 |   <link rel="dns-prefetch" href="https://avatars.githubusercontent.com">
  22 |   <link rel="dns-prefetch" href="https://github-cloud.s3.amazonaws.com">
  23 |   <link rel="dns-prefetch" href="https://user-images.githubusercontent.com/">
  24 |   <link rel="preconnect" href="https://github.githubassets.com" crossorigin>
  25 |   <link rel="preconnect" href="https://avatars.githubusercontent.com">
  26 | 
  27 | 
  28 | 
  29 | 
  30 |   <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/light-74231a1f3bbb.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/dark-8a995f0bacd4.css" /><link data-color-theme="light_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_high_contrast-83beb16e0ecf.css" /><link data-color-theme="light_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_colorblind-f91b0f603451.css" /><link data-color-theme="light_colorblind_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_colorblind_high_contrast-5aebfa54b215.css" /><link data-color-theme="light_tritanopia" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_tritanopia-6e122dab64fc.css" /><link data-color-theme="light_tritanopia_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/light_tritanopia_high_contrast-b32664e28b79.css" /><link data-color-theme="dark_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_high_contrast-9ac301c3ebe5.css" /><link data-color-theme="dark_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind-cd826e8636dc.css" /><link data-color-theme="dark_colorblind_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind_high_contrast-131d53fe187c.css" /><link data-color-theme="dark_tritanopia" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_tritanopia-18119e682df0.css" /><link data-color-theme="dark_tritanopia_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_tritanopia_high_contrast-63c0358957ba.css" /><link data-color-theme="dark_dimmed" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_dimmed-f37fb7684b1f.css" /><link data-color-theme="dark_dimmed_high_contrast" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_dimmed_high_contrast-8f371c75debd.css" />
  31 | 
  32 |     <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-primitives-225433424a87.css" />
  33 |     <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-cba26849680f.css" />
  34 |     <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/global-d579beef0491.css" />
  35 |     <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/github-864568fbf430.css" />
  36 |   <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/repository-4fce88777fa8.css" />
  37 | <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/code-1b0afc3b2d3d.css" />
  38 | 
  39 | 
  40 | 
  41 | 
  42 |   <script type="application/json" id="client-env">{"locale":"en","featureFlags":["alternate_user_config_repo","codespaces_prebuild_region_target_update","contentful_lp_flex_features_actions","contentful_lp_flex_features_code_review","contentful_lp_flex_features_code_search","contentful_lp_flex_features_codespaces","contentful_lp_flex_features_discussions","contentful_lp_flex_features_issues","contentful_lp_footnotes","copilot_chat_custom_instructions","copilot_chat_repo_custom_instructions_preview","copilot_chat_vision_in_claude","copilot_duplicate_thread","copilot_free_to_paid_telem","copilot_immersive_issue_preview","copilot_new_immersive_references_ui","copilot_no_floating_button","copilot_read_shared_conversation","copilot_task_oriented_assistive_prompts","copilot_topics_as_references","copilot_ui_refs","direct_to_salesforce","dotcom_chat_client_side_skills","ghost_pilot_confidence_truncation_25","ghost_pilot_confidence_truncation_40","github_models_o3_mini_streaming","insert_before_patch","issues_dashboard_no_redirects","issues_react_blur_item_picker_on_close","issues_react_create_milestone","issues_react_dashboard_save_query_refresh","issues_react_prohibit_title_fallback","issues_react_remove_placeholders","lifecycle_label_name_updates","link_contact_sales_swp_marketo","marketing_pages_search_explore_provider","memex_mwl_filter_field_delimiter","nonreporting_relay_graphql_status_codes","primer_react_css_modules_ga","primer_react_select_panel_with_modern_action_list","remove_child_patch","sample_network_conn_type","site_proxima_australia_update","swp_enterprise_contact_form","use_paginated_repo_picker_cost_center_form","viewscreen_sandbox"]}</script>
  43 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/wp-runtime-1014be772675.js"></script>
  44 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_oddbird_popover-polyfill_dist_popover-fn_js-81211bd82278.js"></script>
  45 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_mini-throttle_dist_index_js-node_modules_stacktrace-parser_dist_s-1d3d52-4be8ffe9a34a.js"></script>
  46 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_failbot_failbot_ts-f0df83c858f4.js"></script>
  47 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/environment-5b1ec761d845.js"></script>
  48 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_primer_behaviors_dist_esm_index_mjs-0dbb79f97f8f.js"></script>
  49 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_selector-observer_dist_index_esm_js-f690fd9ae3d5.js"></script>
  50 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_relative-time-element_dist_index_js-62d275b7ddd9.js"></script>
  51 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_auto-complete-element_dist_index_js-node_modules_github_catalyst_-8e9f78-a90ac05d2469.js"></script>
  52 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_text-expander-element_dist_index_js-78748950cb0c.js"></script>
  53 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_filter-input-element_dist_index_js-node_modules_github_remote-inp-d8c643-f5192902810f.js"></script>
  54 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_markdown-toolbar-element_dist_index_js-ceef33f593fa.js"></script>
  55 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_file-attachment-element_dist_index_js-node_modules_primer_view-co-07e635-2bb803cf8a63.js"></script>
  56 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/github-elements-570ce1abc70b.js"></script>
  57 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/element-registry-60ac18e3a4d7.js"></script>
  58 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_braintree_browser-detection_dist_browser-detection_js-node_modules_githu-bb80ec-72267f4e3ff9.js"></script>
  59 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_lit-html_lit-html_js-be8cb88f481b.js"></script>
  60 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_morphdom_dist_morphdom-esm_js-0c08218c7d5f.js"></script>
  61 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_fzy_js_index_js-node_modules_github_paste-markdown_dist_index_js-6c00013a3dc4.js"></script>
  62 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_turbo_dist_turbo_es2017-esm_js-a03ee12d659a.js"></script>
  63 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_remote-form_dist_index_js-node_modules_delegated-events_dist_inde-893f9f-b6294cf703b7.js"></script>
  64 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_color-convert_index_js-e3180fe3bcb3.js"></script>
  65 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_quote-selection_dist_index_js-node_modules_github_session-resume_-c1aa61-97c8ff49bc41.js"></script>
  66 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_updatable-content_updatable-content_ts-62f3e9c52ece.js"></script>
  67 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_task-list_ts-app_assets_modules_github_sso_ts-ui_packages-900dde-768abe60b1f8.js"></script>
  68 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_sticky-scroll-into-view_ts-3e000c5d31a9.js"></script>
  69 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_ajax-error_ts-app_assets_modules_github_behaviors_include-d0d0a6-7cc66dc86dd7.js"></script>
  70 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_commenting_edit_ts-app_assets_modules_github_behaviors_ht-83c235-4bcbbbfbe1d4.js"></script>
  71 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/behaviors-3fd3d557b797.js"></script>
  72 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_delegated-events_dist_index_js-node_modules_github_catalyst_lib_index_js-f6223d90c7ba.js"></script>
  73 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/notifications-global-01e85cd1be94.js"></script>
  74 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_mini-throttle_dist_index_js-node_modules_github_catalyst_lib_inde-dbbea9-26cce2010167.js"></script>
  75 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/code-menu-906f56af9b01.js"></script>
  76 | 
  77 |   <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/primer-react-524df54ac6a7.js"></script>
  78 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/react-core-ef39022de09e.js"></script>
  79 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/react-lib-80430c87778a.js"></script>
  80 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/octicons-react-cf2f2ab8dab4.js"></script>
  81 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_emotion_is-prop-valid_dist_emotion-is-prop-valid_esm_js-node_modules_emo-b1c483-fc8b0fafeadf.js"></script>
  82 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_catalyst_lib_index_js-node_modules_tanstack_react-query_build_mod-3b1f5d-85b60118c668.js"></script>
  83 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_dompurify_dist_purify_es_mjs-dd1d3ea6a436.js"></script>
  84 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_lodash-es__Stack_js-node_modules_lodash-es__Uint8Array_js-node_modules_l-4faaa6-4a736fde5c2f.js"></script>
  85 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_lodash-es_isEqual_js-92a85ab8c568.js"></script>
  86 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_tanstack_react-query_build_modern_queryOptions_js-node_modules_react-int-52413b-80f4519d2f5a.js"></script>
  87 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_hydro-analytics-client_dist_analytics-client_js-node_modules_gith-23d21c-98fe23e2e322.js"></script>
  88 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_aria-live_aria-live_ts-ui_packages_history_history_ts-ui_packages_promise-with-re-01dc80-d5f989deb16c.js"></script>
  89 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_paths_index_ts-82d197f7ecc6.js"></script>
  90 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_ref-selector_RefSelector_tsx-1e80bf48ee34.js"></script>
  91 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_commit-attribution_index_ts-ui_packages_commit-checks-status_index_ts-ui_packages-762eaa-9197e3677038.js"></script>
  92 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_diffs_diff-parts_ts-247e577e82a9.js"></script>
  93 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_app-uuid_app-uuid_ts-ui_packages_document-metadata_document-metadata_ts-ui_packag-4d8de9-cf1e55487de3.js"></script>
  94 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_hydro-analytics_hydro-analytics_ts-ui_packages_use-client-value_use-client-value_-fac349-75d5a0c427e5.js"></script>
  95 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/ui_packages_code-view-shared_hooks_use-canonical-object_ts-ui_packages_code-view-shared_hooks-92518b-607604f44ff5.js"></script>
  96 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_blob-anchor_ts-ui_packages_code-nav_code-nav_ts-ui_packages_filter--8253c1-91468a3354f9.js"></script>
  97 | <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/react-code-view-90af2ed12ae7.js"></script>
  98 | <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react.4c9ea3176814ef49b16d.module.css" />
  99 | <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/react-code-view.fa5be0397505b86dfa5f.module.css" />
  100 | 
  101 |   <script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/notifications-subscriptions-menu-8c4cd018ca06.js"></script>
  102 | <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/primer-react.4c9ea3176814ef49b16d.module.css" />
  103 | <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/notifications-subscriptions-menu.e5e6e593370c808590a5.module.css" />
  104 | 
  105 | 
  106 |   <title>security-insights-spec/.github/security-insights.yml at main · ossf/security-insights-spec · GitHub</title>
  107 | 
  108 | 
  109 | 
  110 |   <meta name="route-pattern" content="/:user_id/:repository/blob/*name(/*path)" data-turbo-transient>
  111 |   <meta name="route-controller" content="blob" data-turbo-transient>
  112 |   <meta name="route-action" content="show" data-turbo-transient>
  113 |   <meta name="fetch-nonce" content="03bbf1f4-45d8-c9bd-f0d1-aed38073a815">
  114 | 
  115 | 
  116 |   <meta name="current-catalog-service-hash" content="f3abb0cc802f3d7b95fc8762b94bdcb13bf39634c40c357301c4aa1d67a256fb">
  117 | 
  118 | 
  119 |   <meta name="request-id" content="DB4F:E9D2F:3DFBD2:59CEA0:681B84C1" data-pjax-transient="true"/><meta name="html-safe-nonce" content="4b6513e7db2778f2942b8a42e0327030a7e5d1e67193adc529aef16f4bef3d2f" data-pjax-transient="true"/><meta name="visitor-payload" content="eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJEQjRGOkU5RDJGOjNERkJEMjo1OUNFQTA6NjgxQjg0QzEiLCJ2aXNpdG9yX2lkIjoiNjI4NDAwMTU4MzQ5MzI1MjI4OSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9" data-pjax-transient="true"/><meta name="visitor-hmac" content="734f4dd3153be122cd07b8e721d1898c4ccb510dd45b4f44b0b742bc47ba4672" data-pjax-transient="true"/>
  120 | 
  121 | 
  122 |     <meta name="hovercard-subject-tag" content="repository:448697211" data-turbo-transient>
  123 | 
  124 | 
  125 |   <meta name="github-keyboard-shortcuts" content="repository,source-code,file-tree,copilot" data-turbo-transient="true" />
  126 | 
  127 | 
  128 |   <meta name="selected-link" value="repo_source" data-turbo-transient>
  129 |   <link rel="assets" href="https://github.githubassets.com/">
  130 | 
  131 |     <meta name="google-site-verification" content="Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I">
  132 | 
  133 | <meta name="octolytics-url" content="https://collector.github.com/github/collect" />
  134 | 
  135 |   <meta name="analytics-location" content="/&lt;user-name&gt;/&lt;repo-name&gt;/blob/show" data-turbo-transient="true" />
  136 | 
  137 | 
  138 | 
  139 | 
  140 | 
  141 | 
  142 |     <meta name="user-login" content="">
  143 | 
  144 | 
  145 | 
  146 |     <meta name="viewport" content="width=device-width">
  147 | 
  148 | 
  149 | 
  150 |       <meta name="description" content="Machine-readable specification for the attestation of security-relevant data. - security-insights-spec/.github/security-insights.yml at main · ossf/security-insights-spec">
  151 | 
  152 |       <link rel="search" type="application/opensearchdescription+xml" href="/opensearch.xml" title="GitHub">
  153 | 
  154 |     <link rel="fluid-icon" href="https://github.com/fluidicon.png" title="GitHub">
  155 |     <meta property="fb:app_id" content="1401488693436528">
  156 |     <meta name="apple-itunes-app" content="app-id=1477376905, app-argument=https://github.com/ossf/security-insights-spec/blob/main/.github/security-insights.yml" />
  157 | 
  158 |       <meta name="twitter:image" content="https://opengraph.githubassets.com/ada420191a08ce11bce2f93c1f2b6f401b64ed45d965eaafa7d2d5f89059e9db/ossf/security-insights-spec" /><meta name="twitter:site" content="@github" /><meta name="twitter:card" content="summary_large_image" /><meta name="twitter:title" content="security-insights-spec/.github/security-insights.yml at main · ossf/security-insights-spec" /><meta name="twitter:description" content="Machine-readable specification for the attestation of security-relevant data. - ossf/security-insights-spec" />
  159 |   <meta property="og:image" content="https://opengraph.githubassets.com/ada420191a08ce11bce2f93c1f2b6f401b64ed45d965eaafa7d2d5f89059e9db/ossf/security-insights-spec" /><meta property="og:image:alt" content="Machine-readable specification for the attestation of security-relevant data. - ossf/security-insights-spec" /><meta property="og:image:width" content="1200" /><meta property="og:image:height" content="600" /><meta property="og:site_name" content="GitHub" /><meta property="og:type" content="object" /><meta property="og:title" content="security-insights-spec/.github/security-insights.yml at main · ossf/security-insights-spec" /><meta property="og:url" content="https://github.com/ossf/security-insights-spec/blob/main/.github/security-insights.yml" /><meta property="og:description" content="Machine-readable specification for the attestation of security-relevant data. - ossf/security-insights-spec" />
  160 | 
  161 | 
  162 | 
  163 | 
  164 | 
  165 |       <meta name="hostname" content="github.com">
  166 | 
  167 | 
  168 | 
  169 |         <meta name="expected-hostname" content="github.com">
  170 | 
  171 | 
  172 |   <meta http-equiv="x-pjax-version" content="1028cea5b68ccc3202d41ac577eb5286a40f3ea1114b605b5b741b82f7d813c4" data-turbo-track="reload">
  173 |   <meta http-equiv="x-pjax-csp-version" content="352e51c42d5f5727a7c545752bf34d1f83f40219e7036c6959817149a51651bc" data-turbo-track="reload">
  174 |   <meta http-equiv="x-pjax-css-version" content="c5a28babfb5d8a5876ab14a9f05d0a12c19137c5eeb273b7a6d6b2a25b72d40f" data-turbo-track="reload">
  175 |   <meta http-equiv="x-pjax-js-version" content="21fb624719a602cd436248ef39f5eac960b2432ca10d1389f2fc0cf2e12fa0d1" data-turbo-track="reload">
  176 | 
  177 |   <meta name="turbo-cache-control" content="no-preview" data-turbo-transient="">
  178 | 
  179 |       <meta name="turbo-cache-control" content="no-cache" data-turbo-transient>
  180 | 
  181 |     <meta data-hydrostats="publish">
  182 |   <meta name="go-import" content="github.com/ossf/security-insights-spec git https://github.com/ossf/security-insights-spec.git">
  183 | 
  184 |   <meta name="octolytics-dimension-user_id" content="67707773" /><meta name="octolytics-dimension-user_login" content="ossf" /><meta name="octolytics-dimension-repository_id" content="448697211" /><meta name="octolytics-dimension-repository_nwo" content="ossf/security-insights-spec" /><meta name="octolytics-dimension-repository_public" content="true" /><meta name="octolytics-dimension-repository_is_fork" content="false" /><meta name="octolytics-dimension-repository_network_root_id" content="448697211" /><meta name="octolytics-dimension-repository_network_root_nwo" content="ossf/security-insights-spec" />
  185 | 
  186 | 
  187 | 
  188 | 
  189 | 
  190 |     <meta name="turbo-body-classes" content="logged-out env-production page-responsive">
  191 | 
  192 | 
  193 |   <meta name="browser-stats-url" content="https://api.github.com/_private/browser/stats">
  194 | 
  195 |   <meta name="browser-errors-url" content="https://api.github.com/_private/browser/errors">
  196 | 
  197 |   <meta name="release" content="3e3cc454eb034c06131df5bb06e959eb8caae3e9">
  198 | 
  199 |   <link rel="mask-icon" href="https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg" color="#000000">
  200 |   <link rel="alternate icon" class="js-site-favicon" type="image/png" href="https://github.githubassets.com/favicons/favicon.png">
  201 |   <link rel="icon" class="js-site-favicon" type="image/svg+xml" href="https://github.githubassets.com/favicons/favicon.svg" data-base-href="https://github.githubassets.com/favicons/favicon">
  202 | 
  203 | <meta name="theme-color" content="#1e2327">
  204 | <meta name="color-scheme" content="light dark" />
  205 | 
  206 | 
  207 |   <link rel="manifest" href="/manifest.json" crossOrigin="use-credentials">
  208 | 
  209 |   </head>
  210 | 
  211 |   <body class="logged-out env-production page-responsive" style="word-wrap: break-word;">
  212 |     <div data-turbo-body class="logged-out env-production page-responsive" style="word-wrap
       ^
  212 | : break-word;">
  213 | 
  214 | 
  215 | 
  216 | 
  217 |     
FAIL    github.com/ossf/si-tooling/v2/si        0.768s
FAIL
make: *** [test-cov] Error 1

…arent SI file

Signed-off-by: Travis Truman <trumant@gmail.com>
trumant added a commit to trumant/security-insights-spec that referenced this pull request May 7, 2025
These changes are being made after finding examples in the wild
that provide values like `https://github.com/ossf/security-insights-spec/blob/main/.github/security-insights.yml`
that are unable to be easily consumed by the code in `ossf/si-tooling`

This change relates to the changes in:
- [fix: specific project-si-source URL that provides raw access to the parent SI file](ossf/si-tooling#27)
- ["example" test demonstrating the issue](https://github.com/ossf/si-tooling/pull/26/files#diff-2c7a40d9b54300b2087ef12ec04ebd8ae5be37e4eb341e57cea2e7f9f1bfe5caR8)

Signed-off-by: Travis Truman <trumant@gmail.com>
eddie-knight pushed a commit to ossf/security-insights that referenced this pull request May 7, 2025
These changes are being made after finding examples in the wild
that provide values like `https://github.com/ossf/security-insights-spec/blob/main/.github/security-insights.yml`
that are unable to be easily consumed by the code in `ossf/si-tooling`

This change relates to the changes in:
- [fix: specific project-si-source URL that provides raw access to the parent SI file](ossf/si-tooling#27)
- ["example" test demonstrating the issue](https://github.com/ossf/si-tooling/pull/26/files#diff-2c7a40d9b54300b2087ef12ec04ebd8ae5be37e4eb341e57cea2e7f9f1bfe5caR8)

Signed-off-by: Travis Truman <trumant@gmail.com>
Copy link
Contributor

@eddie-knight eddie-knight left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hah! comical that the SI for the repo that validates SIs is itself invalid

@eddie-knight eddie-knight merged commit 6b79f9a into ossf:main May 7, 2025
1 check passed
@trumant trumant deleted the update-parent-si-url branch May 7, 2025 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants