chore(repo): slim .gt-repo.yaml, and catch up four gt releases - #19
Merged
Conversation
gt 1.3.0 writes only what differs from its defaults. This file was the fully resolved spec, so it pinned all ~25 of them — and a repository that pins a default has silently stopped tracking it, which meant changing an opinion in gt would have reached nobody. 84 lines to 39, with no change to how this repository is governed: 'gt repo config' is identical before and after apart from the gt_version stamp. That stamp was still 1.0.0, so the same sync also picks up a fix this repository had been missing since: dependabot-auto-merge.yml now passes APP_CLIENT_ID and APP_PRIVATE_KEY explicitly rather than relying on 'secrets: inherit', which is documented as working only within one organization and silently passes nothing when the called workflow lives under another owner — as gt's does. Both are optional and resolve to the empty string where no bot App exists.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
gt 1.3.0 writes only what differs from its defaults. This file was the fully resolved spec, so it pinned all ~25 of them.
That is what gt#51 fixed: a repository that pins a default has silently stopped tracking it, so changing an opinion in gt would have reached none of them — and nothing would have reported it, since every repository was compliant by its own file.
84 lines to 39, with no change to how this repository is governed —
gt repo configis byte-identical before and after apart from thegt_versionstamp.The workflow change
That stamp was still 1.0.0, so this sync also picks up a fix the repository has been missing since.
dependabot-auto-merge.ymlnow names its secrets:secrets: inheritis documented as working for reusable workflows "in the same organization or enterprise", and gt lives under a different owner than this repository — so it was passing nothing, silently. The bulwark stage lost its Codecov token to exactly this. Both secrets are optional and resolve to the empty string where the organization has no bot App, which the called workflow treats as "not configured".