🎙️ task - feat: support github rulesets at org and repo level
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 42/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- github, typescript
- Ambito
- backend-api-design
Direzione di ricerca
Inizia leggendo DeclaredGithubBranchProtection e DeclaredGithubEnvironment, quindi i relativi DAO e i test DAO esistenti per comprendere la struttura dei file, la logica di cast, la forma di context/auth e i pattern get/set. Controlla .agent/ e briefs/ prima dell’implementazione. Il lavoro è completato quando gli oggetti ruleset e i DAO con ambito di repository e organizzazione sono registrati ed esportati, coperti da test unitari e di integrazione e superano typecheck, build, lint e format.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
🦫🎙️ dispatch to foreman
💧 task enqueued
├─ priority = ?
├─ yieldage = ?
└─ leverage = ?
title
feat: support github rulesets at org and repo level
description
.what
add support for github rulesets at both repo level and org level, so consumers can declare tag-protection (and branch) rulesets as code via the declastruct get/set pattern.
.why
use case from ahbode/infrastructure: enforce that only a specific github app (release-please) can create tags that match v*. this is the out-of-band half of an aws oidc "prod apply only from a version tag cut from main" guarantee:
- aws sts conditions on
ref_type == tag+ref LIKE refs/tags/v* - a github tag ruleset must restrict
v*creation to the release app only (bypass actor) - release-please runs only on main
today declastruct-github has no ruleset/tag-protection resource (it models DeclaredGithubBranchProtection + DeclaredGithubEnvironment but not rulesets), so this cannot be declared as code.
.deliverables
DeclaredGithubRepoRulesetdomain object (repo-scoped)DeclaredGithubOrgRulesetdomain object (org-scoped; adds repository-scope conditions)- supporter value objects if the repo favors that granularity (rule, bypass actor, conditions) — mirror how
DeclaredGithubBranchProtectionhandles nested shapes DeclaredGithubRepoRulesetDao+DeclaredGithubOrgRulesetDao— get (by primary id, by unique name, by ref) + set (findsert + upsert), to mirror extant DAO idempotency- register/export alongside extant objects + DAOs (no barrel-export forwarders)
- tests to mirror extant DAO tests (unit for cast logic; integration per the repo's test-fns + credentials pattern)
.api reference
- repo rulesets:
GET/POST/PUT/DELETE /repos/{owner}/{repo}/rulesets(+/rulesets/{id}) - org rulesets:
GET/POST/PUT/DELETE /orgs/{org}/rulesets(+/rulesets/{id}) - ruleset fields:
name(natural unique key per scope),target('branch'|'tag'|'push'),enforcement('active'|'evaluate'|'disabled'),bypass_actors[](actor_id,actor_type['Integration'|'Team'|'OrganizationAdmin'|'RepositoryRole'|'DeployKey'],bypass_mode['always'|'pull_request']),conditions(ref_name.include[]/exclude[], e.g.refs/tags/v*, meta~ALL/~DEFAULT_BRANCH),rules[]({ type, parameters? }; types:creation,update,deletion,required_signatures,required_linear_history,non_fast_forward, ...) - org rulesets also support
conditions.repository_name(include/exclude/protected) orrepository_id id= server-assigned primary key;name= natural unique key (per repo, or per org)
.key choices to verify
- repo ruleset:
primary = ['id'],unique = ['name'] - org ruleset: confirm name uniqueness is per-org; key accordingly
- mirror exactly:
DeclaredGithubBranchProtection,DeclaredGithubEnvironment, and their DAOs (names, file layout, cast functions, context/auth shape, get/set verbs, inline io types, one-export-per-file, fail-fast)
.note
- honor the repo's house rules under
.agent/andbriefs/ - get typecheck/build + lint/format green
- write integration tests per the repo's pattern even if creds are unavailable locally; never add failhide/skip stubs
.source
requested from ahbode/infrastructure work on github-environments-vs-aws-oidc (vlad).
- Lingua principale
- TypeScript
- Stelle
- 0
- Fork
- 0
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ehmpathy/declastruct-github
-
🎙️ task - fix(repo): coerce empty-string homepage/description to null (perpetual UPDATE drift)Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 38/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 45/100
Tutte le issue di ehmpathy/declastruct-github
Issue simili
-
fix(data-lake): wizard source step still previews the local slug, not the server-disambiguated oneApertadata-lake
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
enhancement good first issue priority: low size: XS
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Empty label or headline exports the editor hint ("LABEL" / "Headline goes here") into the PNGAperta
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100
-
Spray wall wizard: Done button on the hold review step sits under the navigation header (iOS)Apertabug ios mobile priority:P1
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
streamplace/streamplace#1351 ·
I maintainer di solito rispondono entro 2 giorni