Skip to content

chore(repo): slim .gt-repo.yaml, and catch up four gt releases - #19

Merged
pedromvgomes merged 1 commit into
mainfrom
chore/lean-spec
Aug 22, 2026
Merged

chore(repo): slim .gt-repo.yaml, and catch up four gt releases#19
pedromvgomes merged 1 commit into
mainfrom
chore/lean-spec

Conversation

@pedromvgomes

Copy link
Copy Markdown
Contributor

gt 1.3.0 writes only what differs from its defaults. This file was the fully resolved spec, so it pinned all ~25 of them.

That is what gt#51 fixed: a repository that pins a default has silently stopped tracking it, so changing an opinion in gt would have reached none of them — and nothing would have reported it, since every repository was compliant by its own file.

84 lines to 39, with no change to how this repository is governed — gt repo config is byte-identical before and after apart from the gt_version stamp.

The workflow change

That stamp was still 1.0.0, so this sync also picks up a fix the repository has been missing since. dependabot-auto-merge.yml now names its secrets:

    secrets:
      APP_CLIENT_ID: ${{ secrets.APP_CLIENT_ID }}
      APP_PRIVATE_KEY: ${{ secrets.APP_PRIVATE_KEY }}

secrets: inherit is documented as working for reusable workflows "in the same organization or enterprise", and gt lives under a different owner than this repository — so it was passing nothing, silently. The bulwark stage lost its Codecov token to exactly this. Both secrets are optional and resolve to the empty string where the organization has no bot App, which the called workflow treats as "not configured".

gt 1.3.0 writes only what differs from its defaults. This file was the
fully resolved spec, so it pinned all ~25 of them — and a repository that
pins a default has silently stopped tracking it, which meant changing an
opinion in gt would have reached nobody.

84 lines to 39, with no change to how this repository is
governed: 'gt repo config' is identical before and after apart from the
gt_version stamp.

That stamp was still 1.0.0, so the same sync also picks up a fix this
repository had been missing since: dependabot-auto-merge.yml now passes
APP_CLIENT_ID and APP_PRIVATE_KEY explicitly rather than relying on
'secrets: inherit', which is documented as working only within one
organization and silently passes nothing when the called workflow lives
under another owner — as gt's does. Both are optional and resolve to the
empty string where no bot App exists.
@github-actions

Copy link
Copy Markdown

bulwark

  • scan — no findings

  • coverage — go: 33.7% (baseline 33.7%)

📦 Full bulwark output — complete scan and coverage logs.

@pedromvgomes
pedromvgomes merged commit 51dfca0 into main Aug 22, 2026
10 checks passed
@pedromvgomes
pedromvgomes deleted the chore/lean-spec branch August 22, 2026 05:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant