Skip to content

fix(dot-project): pin DOT_PROJECT_SPEC_VERSION to 1.0.0 and remove DO-02.01 project_path (#502) - #504

Open
DYNOSuprovo wants to merge 1 commit into
darnitdevorg:mainfrom
DYNOSuprovo:fix/dot-project-spec-version-502
Open

DYNOSuprovo wants to merge 1 commit into
darnitdevorg:mainfrom
DYNOSuprovo:fix/dot-project-spec-version-502

Conversation

@DYNOSuprovo

@DYNOSuprovo DYNOSuprovo commented Sep 26, 2026 •

Copy link
Copy Markdown

Summary

Fixes #502.

  1. OSPS-DO-02.01 locator fix:

    • OSPS-DO-02.01 ("Document bug reporting process") previously set project_path = "security.policy", causing bug reporting lookups to resolve to SECURITY.md.
    • Upstream CNCF dot-project SCHEMA.md (1.0.0) has no bug-reporting field; security.policy designates vulnerability reporting contact/process.
    • Removed project_path = "security.policy" from packages/darnit-baseline/src/darnit_baseline/openssf-baseline.toml under [controls."OSPS-DO-02.01".locator], while retaining the discover globs.
  2. DOT_PROJECT_SPEC_VERSION pinning to upstream 1.0.0:

    • Pinned DOT_PROJECT_SPEC_VERSION = "1.0.0" in packages/darnit/src/darnit/context/dot_project.py (previously 1.4.0, which was an internal darnit reconcile counter rather than an upstream specification version).
    • Added reconciliation history notes to the module docstring and comment block explaining that earlier 1.1.0–1.4.0 values were internal counters.
    • Updated existing spec version unit test in tests/darnit/context/test_dot_project.py to assert "1.0.0".
    • Normalized darnit's own .project/project.yaml schema_version from '1.0' to "1.0.0".
  3. Tests:

AI Assistance

  • This PR was prepared with AI assistance.
  • Details: Assisted with investigating upstream CNCF schema definitions, drafting initial locator fixes, and rebasing.

Acceptance Criteria

  • New project.yaml files are written with schema_version: "1.0.0".
  • DO-02.01 never resolves through security.policy.
  • Commits are signed off (git commit -s) and carry Assisted-by: trailer.

@Marc-cn

Marc-cn commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

Tested on Linux, matches #502 item by item. 1219 tests pass in tests/darnit/context + tests/darnit_baseline, ruff clean, project_path gone from the DO-02.01 locator and from CONTROL_REFERENCE_MAPPING, own .project/project.yaml at "1.0.0".Worth noting the upstream-sync test (test_dot_project_upstream.py) still passes at 1.0.0, it hashes upstream's types.go rather than comparing the version string, so the pin doesn't break it.

One process thing: the AI assistance section of the PR template is unfilled. No issue either way, the policy is about whether you can explain the change, not the checkbox, but could you tick one? Keeps it consistent.

LGTM otherwise.

@mlieberman85

Copy link
Copy Markdown
Contributor

Thanks for picking this up. Before we review further: our AI policy asks contributors to disclose AI assistance in the PR description (the template's "AI assistance" section) and add an Assisted-by: trailer when AI was used. Could you update the PR accordingly? Also, in your own words: why did you remove the DO-02.01 locator rather than map it to an existing .project/ field, and what happens to existing .project/project.yaml files that already say schema_version: 1.4.0 after this change?

@mlieberman85 mlieberman85 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. Part of this is now superseded: #552 removed CONTROL_REFERENCE_MAPPING entirely, since references are now declared per remediation as project_reference. After rebasing, please:

  1. Drop the mappings.py change and the test that imports CONTROL_REFERENCE_MAPPING; that test no longer imports.
  2. Keep the TOML removal of project_path = "security.policy" from DO-02.01 (still needed) and the version pin.
  3. Add the AI-assistance disclosure.
  4. Answer my earlier questions on the PR.

If changing what DOT_PROJECT_SPEC_VERSION means is intentional, a note in spec 030 would help reviewers.

Drafted with Claude Code; reviewed and posted by me.

…-02.01 project_path (darnitdevorg#502)

OSPS-DO-02.01 ('Document bug reporting process') previously set project_path = 'security.policy', causing bug reporting lookups to resolve to SECURITY.md. Upstream CNCF dot-project SCHEMA.md (1.0.0) has no bug-reporting field, so remove project_path and retain discover globs.

In addition, pin DOT_PROJECT_SPEC_VERSION to upstream CNCF schema version 1.0.0 (previously 1.4.0, which was an internal darnit reconcile counter), ensuring new project.yaml files conform to upstream validators.

- Remove project_path from OSPS-DO-02.01 locator in openssf-baseline.toml
- Pin DOT_PROJECT_SPEC_VERSION to '1.0.0' with reconciliation history note
- Update unit tests to assert 1.0.0
- Normalize .project/project.yaml schema_version to '1.0.0'
- Add regression test in tests/darnit_baseline/test_dot_project_locator.py

Closes darnitdevorg#502

Assisted-by: Claude (Anthropic) <noreply@anthropic.com>
Signed-off-by: DYNOSuprovo <DYNOSuprovo@users.noreply.github.com>
@DYNOSuprovo
DYNOSuprovo force-pushed the fix/dot-project-spec-version-502 branch from 5dff039 to ddf61f0 Compare October 7, 2026 11:38
@DYNOSuprovo

Copy link
Copy Markdown
Author

Thank you @mlieberman85 for the review and guidance!

Answers to Questions:

  1. Why remove the DO-02.01 locator rather than map to an existing .project/ field?
    Upstream CNCF dot-project schema v1.0.0 defines path references for security policy (security.policy), governance, codeowners, and contributing, but does not define a dedicated field for general bug reporting. Mapping it to security.policy caused general bug reporting lookups to resolve to SECURITY.md (intended strictly for vulnerability disclosures). Removing project_path allows DO-02.01 to resolve cleanly through its discover globs (ISSUE_TEMPLATE, CONTRIBUTING, etc.) without mispointing to security policies.

  2. What happens to existing .project/project.yaml files with schema_version: 1.4.0?
    Existing files specifying 1.4.0 continue to parse normally: DotProjectReader reads the YAML configuration without strictly rejecting newer schema versions. The DOT_PROJECT_SPEC_VERSION = "1.0.0" pin ensures that newly created or reconciled files match the canonical upstream CNCF 1.0.0 specification rather than the internal darnit counter.

Rebase & Updates:

  • Rebased onto latest main.
  • Dropped the mappings.py change and obsolete CONTROL_REFERENCE_MAPPING test per feat: operator config and trust, result authority, candidate integrity, remediation safety (040-043) #552.
  • Retained the openssf-baseline.toml removal of project_path from DO-02.01 and version pin.
  • Added the Assisted-by: trailer and updated the PR description with the AI assistance disclosure.
  • Verified test suite: all 74 unit tests in tests/darnit_baseline/test_dot_project_locator.py and tests/darnit/context/test_dot_project.py pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix the OSPS-DO-02.01 .project/ locator and pin DOT_PROJECT_SPEC_VERSION to upstream 1.0.0

3 participants