Skip to content

.project/ files written by darnit do not conform to the upstream CNCF dot-project schema #498

Description

@mlieberman85

Summary

.project/ is darnit's primary mechanism for project metadata, but the files darnit writes do not conform to the upstream CNCF dot-project schema (cncf/automation utilities/dot-project, SCHEMA.md version 1.0.0 at commit fb391624922b, 2026-09-24):

  1. Schema version. New project.yaml files are seeded with schema_version: "1.4.0" (
    DOT_PROJECT_SPEC_VERSION = "1.4.0"
    , used at #L998). The upstream validator's SupportedSchemaVersions is ["1.0.0"].
  2. security.contact shape. Upstream defines security.contact as an object (email / advisory_url). darnit writes a bare string there (
    if key == "security_contact":
    from darnit.config.schema import SecurityConfig
    if config.security is None:
    config.security = SecurityConfig()
    config.security.contact = value # Unwrapped primitive
    ).
  3. Unknown and relocated fields. The upstream decoder rejects unknown fields and the Project struct has no extension field; some upstream fields (e.g. slug, project_lead, package_managers, landscape) are read into or written from .project/darnit.yaml instead of project.yaml.
  4. Wrong locator. OSPS-DO-02.01 ("Document bug reporting process") uses project_path = "security.policy" ( ), so remediation and lookup treat the security policy as the bug-reporting process.
  5. Non-CNCF projects. maturity_log is required upstream and CNCF-specific, so a project outside the CNCF cannot produce a valid project.yaml.

Impact

Files darnit creates or edits may fail upstream validation and CNCF tooling, and values can be read back with the wrong meaning. Since .project/ is the primary store, darnit should round-trip it faithfully.

Suggested direction

  • Pin darnit to the upstream schema version it actually implements, and add a CI check that validates darnit-written fixtures with the upstream validator.
  • Write security.contact in the upstream object form and read both forms.
  • Keep upstream fields in project.yaml; limit darnit.yaml to darnit-specific keys.
  • Fix the DO-02.01 locator.
  • Propose upstream changes where .project/ cannot express what non-CNCF projects need (making CNCF-only required fields optional, a sanctioned extension mechanism), rather than diverging locally.

Related: #468, #469, #463.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions