Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

lint accepts modelith-ref-type on a GitHub-origin provenance header

Aperta Adatta ai principianti
#54 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
86/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
go
Ambito
tooling

Direzione di ricerca

Inizia in internal/provenance/provenance.go, in Header.validate, poi leggi il test accanto a TestADR_0019_RefTypeIsRecordedOnlyWhereItIsNeeded. Riproduci il problema con modelith lint sull’header di origine GitHub e aggiungi un test che mostri che modelith-ref-type produce una segnalazione di provenance per le origini GitHub, rimanendo valido per il caso documentato di Azure DevOps.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug

Follow-up from the review of #52.

ADR-0019 and docs/10-vendoring.md both say the modelith-ref-type provenance key applies only to Azure DevOps and is omitted for GitHub. Lint doesn't enforce that. Header.validate (internal/provenance/provenance.go) checks only that the value is one of branch/tag/commit, not which origin it appears on.

Repro (at 52a5544)

Take a GitHub-origin vendored copy and add the key. Here the recorded type disagrees with the ref:

# modelith-vendored: DO NOT EDIT — this file is a copy. Change it at its origin.
# modelith-fetch: git
# modelith-origin: https://github.com/acme/billing
# modelith-path: docs/payments.modelith.yaml
# modelith-ref: main
# modelith-ref-type: tag
# modelith-commit: 4f2c1e9c8b3ad0e5f71b2c9a6d4e8f30ab5c7d21
# modelith-imported: 2026-09-23
# modelith-digest: sha256:…
modelith lint gh-reftype.modelith.yaml
# 0 error(s), 0 warning(s)

deps update then drops the key without saying so (recordedRefType returns "" for GitHub).

Expected

Pre-release, the header uses closed sets (compare unknown fetch: methods), so this should be a provenance finding along the lines of ref-type is only recorded for dev.azure.com origins. Pin it with a test next to TestADR_0019_RefTypeIsRecordedOnlyWhereItIsNeeded.

Lingua principale
Go
Stelle
34
Fork
5
Merge medio
5h 7m
PR unite (30g)
6

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di stacklok/modelith

Tutte le issue di stacklok/modelith

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.