Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

feat(core): YAML policy format with transformation functions via `!` tags

Aperta
#375 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
python
Ambito
cli, security

Direzione di ricerca

Inizia con il percorso esistente di validazione e valutazione delle policy JSON, quindi segui gli entry point tirith lint e tirith fmt menzionati nell’issue e il lavoro correlato in #366. Il lavoro è completo quando le policy YAML vengono valutate come quelle JSON, i tag approvati trasformano i valori con errori per ciascun valore, i tag sconosciuti falliscono in modo chiaro, lint/format e i round-trip del builder funzionano e la documentazione include un confronto JSON/YAML.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

enhancement

Policies are JSON-only today. Support YAML as a first-class policy format: the same schema (YAML is
a superset, so every existing policy has a 1:1 YAML twin), plus YAML custom tags — the ! prefix —
as declarative transformation functions inline in the policy:

meta:
  version: v1
  provider: stackguardian/terraform_plan
evaluators:
  - id: task_def_count
    provider_args:
      operation_type: attribute
      terraform_resource_type: aws_ecs_task_definition
      terraform_resource_attribute: !json_decode container_definitions
    condition:
      type: LessThanEqualTo
      value: !length

Design constraints

  • Tags are data, not code: a fixed whitelist of transformation tags (e.g. !length,
    !json_decode, !lower) parsed with a safe YAML loader — an unknown tag is a validation error,
    never an arbitrary constructor. This keeps the format Builder-friendly.
  • The tags are surface syntax over the same transformation pipeline planned for
    condition.transform — one implementation, two spellings. A minimal function set can ship with
    the format; the fuller coercion layer (dates, CIDR, sizes) extends it later.
  • Each transformation step wraps errors per value (a failed decode is a provider error on that
    resource, not a crashed run).
  • tirith lint / tirith fmt (#366) must accept and format YAML policies; validation and the
    interactive builder round-trip both formats.

Acceptance. A .yaml policy evaluates identically to its JSON twin; ! tags apply the shared
transformations with per-value error handling; an unknown tag fails validation with a clear
message; tirith lint/fmt handle YAML; docs show a side-by-side JSON/YAML example.

Lingua principale
Python
Stelle
170
Fork
46
Merge medio
1g 21h
PR unite (30g)
7

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di StackGuardian/tirith

Tutte le issue di StackGuardian/tirith

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.