lint accepts modelith-ref-type on a GitHub-origin provenance header
還沒有人認領這個 Issue。
評估
研究方向
從 internal/provenance/provenance.go 中的 Header.validate 開始,然後閱讀 TestADR_0019_RefTypeIsRecordedOnlyWhereItIsNeeded 旁邊的測試。針對 GitHub-origin header 使用 modelith lint 進行重現,並新增一個測試,顯示 modelith-ref-type 會為 GitHub origins 產生 provenance finding,同時對於文件中說明的 Azure DevOps case 仍然有效。
由索引模型根據 Issue 內容生成。
描述
Follow-up from the review of #52.
ADR-0019 and docs/10-vendoring.md both say the modelith-ref-type provenance key applies only to Azure DevOps and is omitted for GitHub. Lint doesn't enforce that. Header.validate (internal/provenance/provenance.go) checks only that the value is one of branch/tag/commit, not which origin it appears on.
Repro (at 52a5544)
Take a GitHub-origin vendored copy and add the key. Here the recorded type disagrees with the ref:
# modelith-vendored: DO NOT EDIT — this file is a copy. Change it at its origin.
# modelith-fetch: git
# modelith-origin: https://github.com/acme/billing
# modelith-path: docs/payments.modelith.yaml
# modelith-ref: main
# modelith-ref-type: tag
# modelith-commit: 4f2c1e9c8b3ad0e5f71b2c9a6d4e8f30ab5c7d21
# modelith-imported: 2026-09-23
# modelith-digest: sha256:…
modelith lint gh-reftype.modelith.yaml
# 0 error(s), 0 warning(s)
deps update then drops the key without saying so (recordedRefType returns "" for GitHub).
Expected
Pre-release, the header uses closed sets (compare unknown fetch: methods), so this should be a provenance finding along the lines of ref-type is only recorded for dev.azure.com origins. Pin it with a test next to TestADR_0019_RefTypeIsRecordedOnlyWhereItIsNeeded.
- 主要語言
- Go
- 星號
- 34
- 分支
- 5
- 平均合併
- 5 小時 7 分鐘
- 30 天內合併 PR
- 6
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
stacklok/modelith 的其他 Issue
-
enhancement
難度 2/5 1-3 小時 新手友好度 88/100
-
documentation
難度 2/5 1-3 小時 新手友好度 92/100
-
enhancement
難度 2/5 半天 新手友好度 68/100
-
難度 5/5 一週以上 新手友好度 20/100
-
難度 5/5 一週以上 新手友好度 20/100
查看 stacklok/modelith 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 92/100
MagaluCloud/terraform-provider-mgc#323 ·
維護者通常 11 天內回覆
-
難度 2/5 1-3 小時 新手友好度 76/100
rossoctl/context-guru#366 ·
維護者通常 1 天內回覆
-
stage-fail
難度 2/5 1-3 小時 新手友好度 72/100
siyuan-note/bazaar#2293 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 84/100
piraeusdatastore/piraeus-operator#1070 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 68/100
維護者通常 1 天內回覆