Skip to content

feat!: stop reading a repository's .baseline.toml - #556

Merged
mlieberman85 merged 5 commits into
darnitdevorg:mainfrom
mlieberman85:remove-baseline-toml
Oct 5, 2026
Merged

mlieberman85 merged 5 commits into
darnitdevorg:mainfrom
mlieberman85:remove-baseline-toml

Conversation

@mlieberman85

@mlieberman85 mlieberman85 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This completes the .baseline.toml deprecation from feature 040: darnit no longer reads a repository's .baseline.toml for anything.

  • No claims, no extends, no settings, no custom controls, and no trusted path.
  • When the file is present, the audit logs one notice, and the report's warnings carry the same notice: run darnit config migrate.
  • darnit config migrate is unchanged. It reads the file itself and writes the claims to .project/darnit.yaml.

The spec was updated first:

  • docs/architecture/framework-design.md (version alpha.12, sections 2.3 and 14.4, Appendix C);
  • the addendum specs/040-operator-config-trust/deprecation-completed.md;
  • docs/SECURITY_GUIDE.md, CLAUDE.md, and the other docs that described the file.

The code that existed only for this file is removed:

  • load_user_config and its trusted path;
  • darnit.config.user_schema;
  • the deprecation switch and its warnings;
  • .baseline.toml claims;
  • the user-config branches of merge_configs.

apply_user_config is renamed to evaluate_claims, because it still turns .project/ claim evaluation on or off. The CHANGELOG lists the removed APIs under BREAKING.

darnit run gains -f/--framework; until now the file's extends was the only way to pick a framework. An unknown framework name exits 1. With no option, darnit run audits openssf-baseline, the same default as darnit audit.

Depends on

#555 (merged). This branch is rebased onto it.

Type of Change

  • Bug fix (non-breaking change fixing an issue)
  • New feature (non-breaking change adding functionality)
  • Breaking change (fix or feature causing existing functionality to change)
  • Documentation update
  • Refactoring (no functional changes)

Framework Changes Checklist

  • Updated framework spec (docs/architecture/framework-design.md) if behavior changed
  • Ran uv run python scripts/validate_sync.py --verbose and it passes

Testing

  • Tests pass locally (uv run pytest tests/ -v): 5111 passed, 26 skipped; integration tests with GitHub Actions environment variables: 333 passed
  • Added tests for new functionality (if applicable): tests/darnit/config/operator/test_baseline_toml_removed.py, darnit run --framework tests
  • Linting passes (uv run ruff check .)

AI assistance

  • No AI assistance was used
  • AI assistance was used

I used Claude (Claude Code, claude-opus-5-5) to make this change: the spec and docs, the removal, the tests, and the darnit run framework handling. This description was also drafted with Claude. Commits carry an Assisted-by: Claude:claude-opus-5-5 trailer.

Additional Notes

darnit run --framework overlaps with #517, which I'll close with thanks once this merges.

🤖 Generated with Claude Code

framework-design 14.4 now says darnit reads nothing from a repository's
.baseline.toml (no claims, no extends, no settings) and records one notice
pointing at `darnit config migrate`; Appendix C records the removal. The
040 addendum lists what is removed and what stays (config migrate). User
and plugin docs move .baseline.toml examples to operator configuration or
.project/darnit.yaml, and the root example.baseline.toml is deleted.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
`darnit run` reads args.framework but had no option for it (darnitdevorg#507). Add
-f/--framework like `audit` and pass it to the audit state.

The CLI and harness test fixtures selected their framework through a
`.baseline.toml` `extends`; they now pass `--framework testchecks` /
`framework_name="openssf-baseline"` and the fixture files are deleted,
along with the .gitignore rules that kept them tracked.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
darnit no longer reads .baseline.toml for anything: no per-control
status/reason claims (even for a trusted repository), no extends, no
settings or custom controls. When the file is present, the audit logs
one WARNING and adds the same notice to the report's warnings, pointing
at `darnit config migrate`; its keys are no longer listed in
ignored_repository_settings. `darnit config migrate` reads the file
itself and is unchanged (framework-design 14.4, FR-023).

Removed with it: BASELINE_TOML_DEPRECATION_ACTIVE, load_user_config
(and its trusted path), load_user_config_with_report,
validate_user_config, deep_merge, darnit.config.user_schema (UserConfig,
CustomControl, ControlGroup, ...), .baseline.toml claims in
trust.assertions, the user side of merge_configs/merge_control,
EffectiveControl status/is_applicable, EffectiveConfig settings and
get_excluded_controls, the repo_path parameter of load_effective_config*
and the control loaders, and tools.audit get_excluded_control_ids,
get_adapter_for_control, and load_effective_audit_config.
run_checks/run_sieve_audit `apply_user_config` is renamed
`evaluate_claims`: it still gates .project/ claim evaluation.

Tests: test_baseline_toml_removed.py covers the notice, no claims for a
trusted repository, extends ignored, a planted pass not run, and
migrate-then-audit. Tests of the removed loader and schema are deleted;
merge-precedence tests now use operator configuration.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
Replace the unreleased deprecation entries with the BREAKING removal:
one notice pointing at `darnit config migrate`, the removed Python APIs
and renamed parameter, and `darnit run --framework`. The 040 addendum
lists the tools.audit helpers and the evaluate_claims rename too.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…udit

An unknown --framework name loaded nothing and the run reported a clean
result over zero controls, and without --framework the run audited no
controls at all now that .baseline.toml extends is gone. Resolve the
framework the way darnit audit does: an unknown name exits 1, and the
default is openssf-baseline.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
@mlieberman85
mlieberman85 marked this pull request as ready for review October 5, 2026 02:03
@mlieberman85
mlieberman85 merged commit 0c73378 into darnitdevorg:main Oct 5, 2026
8 checks passed
@mlieberman85
mlieberman85 deleted the remove-baseline-toml branch October 5, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant