Repository navigation
fix(dot-project): pin DOT_PROJECT_SPEC_VERSION to 1.0.0 and remove DO-02.01 project_path (#502) - #504
DYNOSuprovo wants to merge 1 commit into
Conversation
|
Tested on Linux, matches #502 item by item. 1219 tests pass in One process thing: the AI assistance section of the PR template is unfilled. No issue either way, the policy is about whether you can explain the change, not the checkbox, but could you tick one? Keeps it consistent. LGTM otherwise. |
|
Thanks for picking this up. Before we review further: our AI policy asks contributors to disclose AI assistance in the PR description (the template's "AI assistance" section) and add an |
mlieberman85
left a comment
There was a problem hiding this comment.
Thanks. Part of this is now superseded: #552 removed CONTROL_REFERENCE_MAPPING entirely, since references are now declared per remediation as project_reference. After rebasing, please:
- Drop the
mappings.pychange and the test that importsCONTROL_REFERENCE_MAPPING; that test no longer imports. - Keep the TOML removal of
project_path = "security.policy"from DO-02.01 (still needed) and the version pin. - Add the AI-assistance disclosure.
- Answer my earlier questions on the PR.
If changing what DOT_PROJECT_SPEC_VERSION means is intentional, a note in spec 030 would help reviewers.
Drafted with Claude Code; reviewed and posted by me.
…-02.01 project_path (darnitdevorg#502) OSPS-DO-02.01 ('Document bug reporting process') previously set project_path = 'security.policy', causing bug reporting lookups to resolve to SECURITY.md. Upstream CNCF dot-project SCHEMA.md (1.0.0) has no bug-reporting field, so remove project_path and retain discover globs. In addition, pin DOT_PROJECT_SPEC_VERSION to upstream CNCF schema version 1.0.0 (previously 1.4.0, which was an internal darnit reconcile counter), ensuring new project.yaml files conform to upstream validators. - Remove project_path from OSPS-DO-02.01 locator in openssf-baseline.toml - Pin DOT_PROJECT_SPEC_VERSION to '1.0.0' with reconciliation history note - Update unit tests to assert 1.0.0 - Normalize .project/project.yaml schema_version to '1.0.0' - Add regression test in tests/darnit_baseline/test_dot_project_locator.py Closes darnitdevorg#502 Assisted-by: Claude (Anthropic) <noreply@anthropic.com> Signed-off-by: DYNOSuprovo <DYNOSuprovo@users.noreply.github.com>
5dff039 to
ddf61f0
Compare
|
Thank you @mlieberman85 for the review and guidance! Answers to Questions:
Rebase & Updates:
|
Summary
Fixes #502.
OSPS-DO-02.01 locator fix:
OSPS-DO-02.01("Document bug reporting process") previously setproject_path = "security.policy", causing bug reporting lookups to resolve toSECURITY.md.SCHEMA.md(1.0.0) has no bug-reporting field;security.policydesignates vulnerability reporting contact/process.project_path = "security.policy"frompackages/darnit-baseline/src/darnit_baseline/openssf-baseline.tomlunder[controls."OSPS-DO-02.01".locator], while retaining thediscoverglobs.DOT_PROJECT_SPEC_VERSIONpinning to upstream 1.0.0:DOT_PROJECT_SPEC_VERSION = "1.0.0"inpackages/darnit/src/darnit/context/dot_project.py(previously1.4.0, which was an internal darnit reconcile counter rather than an upstream specification version).tests/darnit/context/test_dot_project.pyto assert"1.0.0"..project/project.yamlschema_versionfrom'1.0'to"1.0.0".Tests:
tests/darnit_baseline/test_dot_project_locator.pyverifying viatomllibthatOSPS-DO-02.01has noproject_path.tests/darnit/context/test_dot_project.pyandtests/darnit_baseline/test_dot_project_locator.pypass.mainafter feat: operator config and trust, result authority, candidate integrity, remediation safety (040-043) #552 removedCONTROL_REFERENCE_MAPPING.AI Assistance
Acceptance Criteria
project.yamlfiles are written withschema_version: "1.0.0".security.policy.git commit -s) and carryAssisted-by:trailer.