Repository navigation
feat!: stop reading a repository's .baseline.toml - #556
Merged
mlieberman85 merged 5 commits intoOct 5, 2026
Merged
Conversation
framework-design 14.4 now says darnit reads nothing from a repository's .baseline.toml (no claims, no extends, no settings) and records one notice pointing at `darnit config migrate`; Appendix C records the removal. The 040 addendum lists what is removed and what stays (config migrate). User and plugin docs move .baseline.toml examples to operator configuration or .project/darnit.yaml, and the root example.baseline.toml is deleted. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
`darnit run` reads args.framework but had no option for it (darnitdevorg#507). Add -f/--framework like `audit` and pass it to the audit state. The CLI and harness test fixtures selected their framework through a `.baseline.toml` `extends`; they now pass `--framework testchecks` / `framework_name="openssf-baseline"` and the fixture files are deleted, along with the .gitignore rules that kept them tracked. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
darnit no longer reads .baseline.toml for anything: no per-control status/reason claims (even for a trusted repository), no extends, no settings or custom controls. When the file is present, the audit logs one WARNING and adds the same notice to the report's warnings, pointing at `darnit config migrate`; its keys are no longer listed in ignored_repository_settings. `darnit config migrate` reads the file itself and is unchanged (framework-design 14.4, FR-023). Removed with it: BASELINE_TOML_DEPRECATION_ACTIVE, load_user_config (and its trusted path), load_user_config_with_report, validate_user_config, deep_merge, darnit.config.user_schema (UserConfig, CustomControl, ControlGroup, ...), .baseline.toml claims in trust.assertions, the user side of merge_configs/merge_control, EffectiveControl status/is_applicable, EffectiveConfig settings and get_excluded_controls, the repo_path parameter of load_effective_config* and the control loaders, and tools.audit get_excluded_control_ids, get_adapter_for_control, and load_effective_audit_config. run_checks/run_sieve_audit `apply_user_config` is renamed `evaluate_claims`: it still gates .project/ claim evaluation. Tests: test_baseline_toml_removed.py covers the notice, no claims for a trusted repository, extends ignored, a planted pass not run, and migrate-then-audit. Tests of the removed loader and schema are deleted; merge-precedence tests now use operator configuration. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
Replace the unreleased deprecation entries with the BREAKING removal: one notice pointing at `darnit config migrate`, the removed Python APIs and renamed parameter, and `darnit run --framework`. The 040 addendum lists the tools.audit helpers and the evaluate_claims rename too. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…udit An unknown --framework name loaded nothing and the run reported a clean result over zero controls, and without --framework the run audited no controls at all now that .baseline.toml extends is gone. Resolve the framework the way darnit audit does: an unknown name exits 1, and the default is openssf-baseline. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
mlieberman85
force-pushed
the
remove-baseline-toml
branch
from
October 5, 2026 02:03
e245019 to
5c1107b
Compare
mlieberman85
marked this pull request as ready for review
October 5, 2026 02:03
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This completes the
.baseline.tomldeprecation from feature 040: darnit no longer reads a repository's.baseline.tomlfor anything.extends, no settings, no custom controls, and no trusted path.darnit config migrate.darnit config migrateis unchanged. It reads the file itself and writes the claims to.project/darnit.yaml.The spec was updated first:
docs/architecture/framework-design.md(version alpha.12, sections 2.3 and 14.4, Appendix C);specs/040-operator-config-trust/deprecation-completed.md;docs/SECURITY_GUIDE.md,CLAUDE.md, and the other docs that described the file.The code that existed only for this file is removed:
load_user_configand its trusted path;darnit.config.user_schema;.baseline.tomlclaims;merge_configs.apply_user_configis renamed toevaluate_claims, because it still turns.project/claim evaluation on or off. The CHANGELOG lists the removed APIs under BREAKING.darnit rungains-f/--framework; until now the file'sextendswas the only way to pick a framework. An unknown framework name exits 1. With no option,darnit runauditsopenssf-baseline, the same default asdarnit audit.Depends on
#555 (merged). This branch is rebased onto it.
Type of Change
Framework Changes Checklist
docs/architecture/framework-design.md) if behavior changeduv run python scripts/validate_sync.py --verboseand it passesTesting
uv run pytest tests/ -v): 5111 passed, 26 skipped; integration tests with GitHub Actions environment variables: 333 passedtests/darnit/config/operator/test_baseline_toml_removed.py,darnit run --frameworktestsuv run ruff check .)AI assistance
I used Claude (Claude Code, claude-opus-5-5) to make this change: the spec and docs, the removal, the tests, and the
darnit runframework handling. This description was also drafted with Claude. Commits carry anAssisted-by: Claude:claude-opus-5-5trailer.Additional Notes
darnit run --frameworkoverlaps with #517, which I'll close with thanks once this merges.🤖 Generated with Claude Code